SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Zero-Day Crisis: CVE-2025-20393 Unpatched on Cisco Email Gateways, Exploited by China-Linked Hackers
Zero-Day Crisis: CVE-2025-20393 Unpatched on Cisco Email Gateways, Exploited by China-Linked Hackers

CVE Research

Zero-Day Crisis: CVE-2025-20393 Unpatched on Cisco Email Gateways, Exploited by China-Linked Hackers

Network edge devices continue to be a primary target for sophisticated state-sponsored actors aiming to bypass traditional perimeter defenses. Recent disclosures reveal a critical zero-day vulnerability in Cisco’s Secure Email Gateway (SEG) and Secure Web Manager (SMA) appliances is being actively e...

Apr 28, 2026 • 5 min read

Open No Credentials Required: FortiGate SAML SSO Exploit Path Explained
No Credentials Required: FortiGate SAML SSO Exploit Path Explained

CVE Research

No Credentials Required: FortiGate SAML SSO Exploit Path Explained

Two maximum severity vulnerabilities have been identified in a range of Fortinet products, including the widely deployed FortiGate firewalls. These vulnerabilities, designated as CVE-2025-59718 and CVE-2025-59719, carry a CVSS score of 9.8, indicating their critical impact. The flaws allow for an u...

Apr 28, 2026 • 4 min read

Open Legacy FortiOS Bug Exploited to Bypass Authentication
Legacy FortiOS Bug Exploited to Bypass Authentication

CVE Research

Legacy FortiOS Bug Exploited to Bypass Authentication

In the realm of cybersecurity, vulnerabilities are a constant concern, and the repercussions of neglecting older flaws can be significant. A recent example of this is the active exploitation of a five-year-old vulnerability in Fortinet’s FortiOS SSL VPN, identified as CVE-2020-12812. This flaw allow...

Apr 28, 2026 • 3 min read

Open AISURU Botnet: Inside the 29.7 Tbps Mega-Scale DDoS Weapon
AISURU Botnet: Inside the 29.7 Tbps Mega-Scale DDoS Weapon

CVE Research

AISURU Botnet: Inside the 29.7 Tbps Mega-Scale DDoS Weapon

AISURU is one of the most powerful and rapidly expanding botnets observed in recent years. With an estimated 300,000 compromised routers, DVRs, gateways, and IoT devices, it has played a central role in the unprecedented surge of global DDoS attack peaks in 2025, reaching up to 29.7 Tbps. AISURU’s t...

Apr 28, 2026 • 5 min read

Open CVE-2025-55182: Immediate Operationalization of React2Shell by China-Nexus Threat Actors
CVE-2025-55182: Immediate Operationalization of React2Shell by China-Nexus Threat Actors

CVE Research

CVE-2025-55182: Immediate Operationalization of React2Shell by China-Nexus Threat Actors

Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, security researchers observed active exploitation attempts from several China-nexus cyber threat groups, including Earth Lamia and Jackpot Panda. This critical unauthenticated remote code execution vulnerabili...

Apr 28, 2026 • 4 min read

Open Stealth Fix: Microsoft Patches Exploited LNK Security Hole
Stealth Fix: Microsoft Patches Exploited LNK Security Hole

CVE Research

Stealth Fix: Microsoft Patches Exploited LNK Security Hole

In a move that highlights the ongoing cat-and-mouse game between software vendors and threat actors, Microsoft has recently addressed a high-severity vulnerability in Windows LNK files. Tracked as CVE-2025-9491, this flaw has been actively exploited in the wild by a multitude of state-sponsored and ...

Apr 28, 2026 • 4 min read

Open AWS Intelligence Report: GRU-Linked Hackers Behind Sustained Infrastructure Attacks
AWS Intelligence Report: GRU-Linked Hackers Behind Sustained Infrastructure Attacks

CVE Research

AWS Intelligence Report: GRU-Linked Hackers Behind Sustained Infrastructure Attacks

Cybercriminals and nation-state advanced persistent threat (APT) groups are increasingly adopting stealth-driven, persistence-focused operational models that rely less on zero-day exploits and more on abusing misconfigurations, credential replay, and trusted infrastructure. Recent disclosures from A...

Apr 28, 2026 • 5 min read

Open SonicWall Disclosure: Active Attacks Target SMA 100, CVE-2025-40602 Patched
SonicWall Disclosure: Active Attacks Target SMA 100, CVE-2025-40602 Patched

CVE Research

SonicWall Disclosure: Active Attacks Target SMA 100, CVE-2025-40602 Patched

SonicWall has released security updates to remediate an actively exploited local privilege escalation vulnerability, tracked as CVE-2025-40602, affecting Secure Mobile Access (SMA) 100 series appliances. The flaw exists in the Appliance Management Console (AMC) and has been confirmed to be exploited...

Apr 28, 2026 • 3 min read

Open CVE-2025-13223: The Chrome Vulnerability You Can’t Afford to Ignore
CVE-2025-13223: The Chrome Vulnerability You Can’t Afford to Ignore

CVE Research

CVE-2025-13223: The Chrome Vulnerability You Can’t Afford to Ignore

Heads up, Chrome users! An actively exploited zero-day vulnerability, CVE-2025-13223, has been identified in Google Chrome’s V8 JavaScript and WebAssembly engine. This vulnerability could allow attackers to execute arbitrary code or cause program crashes. Google has already released security updates...

Apr 28, 2026 • 3 min read