SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open UNK_MassTraction Exploits Critical Roundcube Vulnerabilities to Compromise University Mail Servers
UNK_MassTraction Exploits Critical Roundcube Vulnerabilities to Compromise University Mail Servers

CVE Research

UNK_MassTraction Exploits Critical Roundcube Vulnerabilities to Compromise University Mail Servers

A suspected China-aligned threat cluster, tracked as UNK_MassTraction, is actively targeting vulnerable Roundcube webmail servers at U.S. and Canadian universities. The campaign exploits two critical Roundcube vulnerabilities to steal credentials, bypass two-factor authentication, deploy web shells or VShell, and establish persistent access to institutional mail servers while minimizing forensic evidence.

Jul 08, 2026 • 4 min read

Open CVE-2026-11405: Actively Exploited Zero-Day Hidden Admin Backdoor Threatens Tenda Routers
CVE-2026-11405: Actively Exploited Zero-Day Hidden Admin Backdoor Threatens Tenda Routers

CVE Research

CVE-2026-11405: Actively Exploited Zero-Day Hidden Admin Backdoor Threatens Tenda Routers

A critical advisory about a hidden administrative backdoor embedded in multiple Tenda router firmware builds has been released. Tracked as CVE-2026-11405, the flaw lets an unauthenticated attacker walk straight into the device's web management interface with full admin rights. With no official patch available, it stands as an active zero-day that opportunistic scanners are already probing for.

Jul 08, 2026

Open JADEPUFFER: Understanding Autonomous AI-Driven Ransomware
JADEPUFFER: Understanding Autonomous AI-Driven Ransomware

CVE Research

JADEPUFFER: Understanding Autonomous AI-Driven Ransomware

Jul 06, 2026 • 6 min read

Open Granted Without Asking: How CVE-2026-48558 Lets TaskWeaver and Djinn Stealer Walk in the Front Door
Granted Without Asking: How CVE-2026-48558 Lets TaskWeaver and Djinn Stealer Walk in the Front Door

CVE Research

Granted Without Asking: How CVE-2026-48558 Lets TaskWeaver and Djinn Stealer Walk in the Front Door

A maximum-severity authentication bypass in SimpleHelp's OIDC flow, CVE-2026-48558, is being actively exploited to hijack technician sessions, even past MFA. Attackers use this access to deploy TaskWeaver, a stealth Node.js loader disguised as jQuery, then Djinn Stealer, which harvests cloud, developer, AI-assistant, and crypto-wallet credentials. Now in CISA's KEV catalog with a CVSS of 10.0, this is an urgent, assume-compromise scenario for any SimpleHelp OIDC deployment.

Jul 03, 2026

Open CitrixBleed 2 Powers Anubis Ransomware Intrusions
CitrixBleed 2 Powers Anubis Ransomware Intrusions

CVE Research

CitrixBleed 2 Powers Anubis Ransomware Intrusions

Jul 03, 2026

Open RustDuck: The DDoS Botnet Engineered to Outlast Detection
RustDuck: The DDoS Botnet Engineered to Outlast Detection

CVE Research

RustDuck: The DDoS Botnet Engineered to Outlast Detection

RustDuck is an actively developed DDoS botnet targeting routers, cameras, and servers through known CVEs and default credential abuse, deploying a Rust-based payload with Noise protocol-grade C2 encryption and a weighted sandbox evasion system to build resilient, hard-to-detect flood infrastructure.

Jul 02, 2026

Open Citrix Critical Update: NetScaler Vulnerabilities Fixed Enabling File Leakage and Service Disruption
Citrix Critical Update: NetScaler Vulnerabilities Fixed Enabling File Leakage and Service Disruption

CVE Research

Citrix Critical Update: NetScaler Vulnerabilities Fixed Enabling File Leakage and Service Disruption

Citrix has issued critical fixes for six NetScaler vulnerabilities that could lead to arbitrary file reads, memory disclosure, and denial-of-service attacks. As internet-facing appliances, NetScaler deployments remain attractive targets for threat actors seeking initial access to enterprise networks.

Jul 02, 2026

Open Breaking Down CVE-2026-43503: Dirty Clone Linux Kernel Privilege Escalation Vulnerability

Breaking Down CVE-2026-43503: Dirty Clone Linux Kernel Privilege Escalation Vulnerability

CVE Research

Breaking Down CVE-2026-43503: Dirty Clone Linux Kernel Privilege Escalation Vulnerability

Jun 29, 2026

Open CVE-2026-31431: Hardening Linux Against Copy Fail - Patching, Containment, and Defense-in-Depth
CVE-2026-31431: Hardening Linux Against Copy Fail - Patching, Containment, and Defense-in-Depth

CVE Research

CVE-2026-31431: Hardening Linux Against Copy Fail - Patching, Containment, and Defense-in-Depth

Jun 29, 2026