SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Zero-Day Crisis: CVE-2025-20393 Unpatched on Cisco Email Gateways, Exploited by China-Linked Hackers
Network edge devices continue to be a primary target for sophisticated state-sponsored actors aiming to bypass traditional perimeter defenses. Recent disclosures reveal a critical zero-day vulnerability in Cisco’s Secure Email Gateway (SEG) and Secure Web Manager (SMA) appliances is being actively e...

CVE Research
No Credentials Required: FortiGate SAML SSO Exploit Path Explained
Two maximum severity vulnerabilities have been identified in a range of Fortinet products, including the widely deployed FortiGate firewalls. These vulnerabilities, designated as CVE-2025-59718 and CVE-2025-59719, carry a CVSS score of 9.8, indicating their critical impact. The flaws allow for an u...

CVE Research
Legacy FortiOS Bug Exploited to Bypass Authentication
In the realm of cybersecurity, vulnerabilities are a constant concern, and the repercussions of neglecting older flaws can be significant. A recent example of this is the active exploitation of a five-year-old vulnerability in Fortinet’s FortiOS SSL VPN, identified as CVE-2020-12812. This flaw allow...

CVE Research
AISURU Botnet: Inside the 29.7 Tbps Mega-Scale DDoS Weapon
AISURU is one of the most powerful and rapidly expanding botnets observed in recent years. With an estimated 300,000 compromised routers, DVRs, gateways, and IoT devices, it has played a central role in the unprecedented surge of global DDoS attack peaks in 2025, reaching up to 29.7 Tbps. AISURU’s t...

CVE Research
CVE-2025-55182: Immediate Operationalization of React2Shell by China-Nexus Threat Actors
Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, security researchers observed active exploitation attempts from several China-nexus cyber threat groups, including Earth Lamia and Jackpot Panda. This critical unauthenticated remote code execution vulnerabili...

CVE Research
Stealth Fix: Microsoft Patches Exploited LNK Security Hole
In a move that highlights the ongoing cat-and-mouse game between software vendors and threat actors, Microsoft has recently addressed a high-severity vulnerability in Windows LNK files. Tracked as CVE-2025-9491, this flaw has been actively exploited in the wild by a multitude of state-sponsored and ...

CVE Research
AWS Intelligence Report: GRU-Linked Hackers Behind Sustained Infrastructure Attacks
Cybercriminals and nation-state advanced persistent threat (APT) groups are increasingly adopting stealth-driven, persistence-focused operational models that rely less on zero-day exploits and more on abusing misconfigurations, credential replay, and trusted infrastructure. Recent disclosures from A...

CVE Research
SonicWall Disclosure: Active Attacks Target SMA 100, CVE-2025-40602 Patched
SonicWall has released security updates to remediate an actively exploited local privilege escalation vulnerability, tracked as CVE-2025-40602, affecting Secure Mobile Access (SMA) 100 series appliances. The flaw exists in the Appliance Management Console (AMC) and has been confirmed to be exploited...

CVE Research
CVE-2025-13223: The Chrome Vulnerability You Can’t Afford to Ignore
Heads up, Chrome users! An actively exploited zero-day vulnerability, CVE-2025-13223, has been identified in Google Chrome’s V8 JavaScript and WebAssembly engine. This vulnerability could allow attackers to execute arbitrary code or cause program crashes. Google has already released security updates...
