SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
UNK_MassTraction Exploits Critical Roundcube Vulnerabilities to Compromise University Mail Servers
A suspected China-aligned threat cluster, tracked as UNK_MassTraction, is actively targeting vulnerable Roundcube webmail servers at U.S. and Canadian universities. The campaign exploits two critical Roundcube vulnerabilities to steal credentials, bypass two-factor authentication, deploy web shells or VShell, and establish persistent access to institutional mail servers while minimizing forensic evidence.

CVE Research
CVE-2026-11405: Actively Exploited Zero-Day Hidden Admin Backdoor Threatens Tenda Routers
A critical advisory about a hidden administrative backdoor embedded in multiple Tenda router firmware builds has been released. Tracked as CVE-2026-11405, the flaw lets an unauthenticated attacker walk straight into the device's web management interface with full admin rights. With no official patch available, it stands as an active zero-day that opportunistic scanners are already probing for.

CVE Research
Granted Without Asking: How CVE-2026-48558 Lets TaskWeaver and Djinn Stealer Walk in the Front Door
A maximum-severity authentication bypass in SimpleHelp's OIDC flow, CVE-2026-48558, is being actively exploited to hijack technician sessions, even past MFA. Attackers use this access to deploy TaskWeaver, a stealth Node.js loader disguised as jQuery, then Djinn Stealer, which harvests cloud, developer, AI-assistant, and crypto-wallet credentials. Now in CISA's KEV catalog with a CVSS of 10.0, this is an urgent, assume-compromise scenario for any SimpleHelp OIDC deployment.

CVE Research
RustDuck: The DDoS Botnet Engineered to Outlast Detection
RustDuck is an actively developed DDoS botnet targeting routers, cameras, and servers through known CVEs and default credential abuse, deploying a Rust-based payload with Noise protocol-grade C2 encryption and a weighted sandbox evasion system to build resilient, hard-to-detect flood infrastructure.

CVE Research
Citrix Critical Update: NetScaler Vulnerabilities Fixed Enabling File Leakage and Service Disruption
Citrix has issued critical fixes for six NetScaler vulnerabilities that could lead to arbitrary file reads, memory disclosure, and denial-of-service attacks. As internet-facing appliances, NetScaler deployments remain attractive targets for threat actors seeking initial access to enterprise networks.
Breaking Down CVE-2026-43503: Dirty Clone Linux Kernel Privilege Escalation Vulnerability



