SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Serv-U Vulnerabilities Expose Systems to Root Compromise
SolarWinds has released updates to address four critical security flaws in its Serv-U file transfer software that, if successfully exploited, could result in remote code execution. These vulnerabilities affect SolarWinds Serv-U version 15.5 and have been addressed in version 15.5.4.

CVE Research
7,000 Servers and Counting: The Rise of the SSHStalker Linux Botnet
Cybercriminal groups and opportunistic botnet operators continue to shift toward scale-first, persistence-driven operations that rely heavily on misconfigurations, weak authentication, and long-tail vulnerabilities rather than sophisticated zero-days. Recent analyses by Flare and other cybersecurity...

CVE Research
Silent Scan, Stolen Secrets: Kimsuky’s QR-Code Phishing Campaign
A sustained quishing (QR-code phishing) campaign conducted by the North Korea–linked APT group Kimsuky (aka Larva-24005) has been actively targeting government, defense, and critical infrastructure organizations. According to a recent FBI warning, Kimsuky operators embed malicious QR codes in emails...

CVE Research
Weaponizing CVE-2026-1731: VShell and SparkRAT in Real-World BeyondTrust Breaches
On February 6, 2026, BeyondTrust disclosed a critical pre-authentication remote code execution vulnerability, CVE-2026-1731, affecting its Remote Support and Privileged Remote Access products. The flaw, assigned a CVSS v4 score of 9.9, enables unauthenticated attackers to execute arbitrary operating...

CVE Research
Supply Chain Risk: Critical Flaws Identified in Popular VS Code Extensions
In the modern software development ecosystem, Integrated Development Environments (IDEs) such as Microsoft Visual Studio Code have become foundational to daily engineering workflows. To extend functionality and streamline development tasks, teams frequently rely on third-party extensions from the ma...

CVE Research
Ongoing Web Shell Attacks Hit 900+ FreePBX Systems: INJ3CTOR3 Behind EncystPHP Deployment
Cybercriminals continue to exploit misconfigurations and unpatched VoIP infrastructure, with over 900 Sangoma FreePBX systems confirmed compromised following widespread deployment of EncystPHP, a malicious PHP-based web shell. These intrusions have been attributed to threat activity leveraging a pos...

CVE Research
Security Advisory: VMware Aria Operations Vulnerabilities May Lead to Remote Compromise
Broadcom has released security updates to address multiple vulnerabilities in VMware Aria Operations, an IT operations management platform that monitors and optimizes virtual, cloud, and hybrid environments. The solution provides performance monitoring, capacity planning, automated alerting, and cos...

CVE Research
From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear
Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, affecting FortiOS, FortiManager, FortiAnalyzer, FortiWeb and FortiProxy. The vulnerability, with a CVSS score of 9.4, is actively exploited in the wild, making it crucial for organizations to apply the necessary p...

CVE Research
WinRAR CVE-2025-8088: RomCom’s Doorway to Remote Code Execution
A critical vulnerability in WinRAR, identified as CVE-2025-8088, was exploited as a zero-day in targeted phishing attacks to deploy RomCom backdoors. This flaw, a directory traversal vulnerability, allows attackers to craft malicious archives that place executable files in Windows Startup folders, e...
