SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Under UNC6384’s LNK: CVE-2025-9491 Powers PlugX Espionage Attacks
Under UNC6384’s LNK: CVE-2025-9491 Powers PlugX Espionage Attacks

CVE Research

Under UNC6384’s LNK: CVE-2025-9491 Powers PlugX Espionage Attacks

A Windows LNK (shortcut) UI-misrepresentation vulnerability (CVE-2025-9491, ZDI-CAN-25373) is being actively exploited by a China-linked threat actor tracked as UNC6384 to deliver the PlugX Remote Access Trojan (RAT) against European diplomatic and government targets. The flaw enables malicious .LNK...

Apr 28, 2026 • 5 min read

Open Critical Security Update: SolarWinds Remediates Multiple Serv-U Vulnerabilities
Critical Security Update: SolarWinds Remediates Multiple Serv-U Vulnerabilities

CVE Research

Critical Security Update: SolarWinds Remediates Multiple Serv-U Vulnerabilities

SolarWinds has issued an urgent security update for its Serv-U file transfer software, patching three critical remote code execution (RCE) vulnerabilities, each rated CVSS 9.1. These flaws could allow attackers with administrative access to execute arbitrary code and compromise vulnerable systems. T...

Apr 28, 2026 • 3 min read

Open ShadowPad’s Silent Invasion: Crafting Persistence Through WSUS Exploitation
ShadowPad’s Silent Invasion: Crafting Persistence Through WSUS Exploitation

CVE Research

ShadowPad’s Silent Invasion: Crafting Persistence Through WSUS Exploitation

The ShadowPad malware campaign represents an urgent and advanced cybersecurity threat, exploiting a critical vulnerability in Microsoft’s WSUS service to gain full system access. This highly modular backdoor is being actively leveraged by state-aligned threat actors to target key sectors globally, e...

Apr 28, 2026 • 6 min read

Open APT24’s BADAUDIO: A Deep Dive into China-Nexus Espionage Against Taiwan
APT24’s BADAUDIO: A Deep Dive into China-Nexus Espionage Against Taiwan

CVE Research

APT24’s BADAUDIO: A Deep Dive into China-Nexus Espionage Against Taiwan

A China-nexus threat actor has been conducting a sophisticated, multi-year espionage campaign using a custom malware downloader, compromising regional infrastructure and reaching over 1,000 global domains through strategic supply chain attacks. At the core of this operation is BADAUDIO, a highly obf...

Apr 28, 2026 • 6 min read

Open 7-Zip Users at Risk: Symbolic Link Vulnerability Triggers RCE Attacks
7-Zip Users at Risk: Symbolic Link Vulnerability Triggers RCE Attacks

CVE Research

7-Zip Users at Risk: Symbolic Link Vulnerability Triggers RCE Attacks

A security vulnerability in the widely used 7-Zip file archiver has recently come under active exploitation. The flaw, identified as CVE-2025-11001, poses a significant risk as it allows for remote code execution. This issue has prompted warnings from cybersecurity entities, including NHS England Di...

Apr 28, 2026 • 3 min read

Open WrtHug Abuse of ASUS WRT Vulnerabilities Exposes Thousands of EoL Routers
WrtHug Abuse of ASUS WRT Vulnerabilities Exposes Thousands of EoL Routers

CVE Research

WrtHug Abuse of ASUS WRT Vulnerabilities Exposes Thousands of EoL Routers

Operation WrtHug refers to a widespread compromise of end-of-life (EoL) ASUS routers, where attackers exploit previously disclosed vulnerabilities to gain control over large numbers of unsupported devices. The activity has impacted tens of thousands of systems, with most cases identified in Taiwan, ...

Apr 28, 2026 • 5 min read

Open One Key to Rule Them All: Apache Syncope Flaw Leaves Passwords Wide Open
One Key to Rule Them All: Apache Syncope Flaw Leaves Passwords Wide Open

CVE Research

One Key to Rule Them All: Apache Syncope Flaw Leaves Passwords Wide Open

A critical vulnerability, identified as CVE-2025-65998, has been discovered in Apache Syncope, a widely-used open-source identity management system, potentially exposing sensitive password information. This flaw highlights the risks associated with hard-coded encryption keys and the importance of pr...

Apr 28, 2026 • 3 min read

Open Grafana Vulnerability Disclosure: SCIM Flaw Could Lead to Privilege Escalation
Grafana Vulnerability Disclosure: SCIM Flaw Could Lead to Privilege Escalation

CVE Research

Grafana Vulnerability Disclosure: SCIM Flaw Could Lead to Privilege Escalation

The discovery of CVE-2025-41115 exposes a critical security weakness in the Grafana Enterprise SCIM (System for Cross-domain Identity Management) component, enabling attackers to escalate privileges or impersonate existing users under specific configuration conditions. This flaw poses a significant ...

Apr 28, 2026 • 3 min read

Open Story of Cyberattack: Salesforce Supply Chain Breach
Story of Cyberattack: Salesforce Supply Chain Breach

CVE Research

Story of Cyberattack: Salesforce Supply Chain Breach

The Salesforce ecosystem just got a harsh reminder that the weakest link rarely lives inside the core platform. It often hides in a trusted third-party app with broad permissions and quietly forgotten tokens.

Apr 28, 2026 • 6 min read