SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Critical Google Chrome Vulnerabilities Patched: WebGPU and V8 Flaws Fixed in Latest Release
Critical Google Chrome Vulnerabilities Patched: WebGPU and V8 Flaws Fixed in Latest Release

CVE Research

Critical Google Chrome Vulnerabilities Patched: WebGPU and V8 Flaws Fixed in Latest Release

Google has urgently released a security update for Chrome, addressing multiple vulnerabilities that could allow attackers to execute code remotely on affected systems.

Apr 28, 2026 • 3 min read

Open Microsoft Tackles 6 Zero-Days and 172 Fixes in October 2025 Patch Tuesday
Microsoft Tackles 6 Zero-Days and 172 Fixes in October 2025 Patch Tuesday

CVE Research

Microsoft Tackles 6 Zero-Days and 172 Fixes in October 2025 Patch Tuesday

The second Tuesday of the month has arrived, and so has another major round of Microsoft security updates. For October 2025, Microsoft has released fixes for a total of 172 vulnerabilities, including 6 actively exploited zero-day flaws and 8 rated as Critical in severity.

Apr 28, 2026 • 7 min read

Open SAP November Patch Roundup: Critical Flaws Demand Immediate Action
SAP November Patch Roundup: Critical Flaws Demand Immediate Action

CVE Research

SAP November Patch Roundup: Critical Flaws Demand Immediate Action

SAP has recently rolled out its November security updates, aiming to resolve a spectrum of vulnerabilities across its enterprise software suite. These updates address critical issues, emphasizing the need for organizations to promptly review and apply the necessary patches to safeguard their SAP env...

Apr 28, 2026 • 3 min read

Open Pre-Auth and Persistent: How a Sophisticated APT Targeted Cisco ISE and Citrix Gateways
Pre-Auth and Persistent: How a Sophisticated APT Targeted Cisco ISE and Citrix Gateways

CVE Research

Pre-Auth and Persistent: How a Sophisticated APT Targeted Cisco ISE and Citrix Gateways

Amazon’s security teams have made a critical discovery, revealing a sophisticated Advanced Persistent Threat (APT) campaign actively exploiting zero-day vulnerabilities in two widely deployed enterprise solutions: Cisco Identity Service Engine (ISE) and Citrix NetScaler ADC/Gateway products. This fi...

Apr 28, 2026 • 5 min read

Open Watch Your Cloud Hygiene Evolve: Trend Analysis in Saner Cloud CHS
Watch Your Cloud Hygiene Evolve: Trend Analysis in Saner Cloud CHS

CVE Research

Watch Your Cloud Hygiene Evolve: Trend Analysis in Saner Cloud CHS

Cloud environments are dynamic!New resources are spun up in seconds, configurations change constantly, and threats evolve even faster. In such a complex landscape, cloud security hygiene isn’t a one-time check, but a continuous journey. To help organizations track this journey, Saner Cloud introduce...

Apr 28, 2026 • 3 min read

Open RelayState Ruse: Exploiting Reflected XSS in Citrix NetScaler
RelayState Ruse: Exploiting Reflected XSS in Citrix NetScaler

CVE Research

RelayState Ruse: Exploiting Reflected XSS in Citrix NetScaler

In the realm of cybersecurity, it’s not uncommon to stumble upon vulnerabilities while dissecting a system during the pursuit of reproducing an N-day. Security researchers at watchTowr Labs recently encountered such a scenario while analyzing CitrixBleed2 (CVE?2025?5777), which affected Citrix NetSc...

Apr 28, 2026 • 3 min read

Open Active Campaign Against Triofox: How Attackers Bypassed Setup and Gained SYSTEM Execution
Active Campaign Against Triofox: How Attackers Bypassed Setup and Gained SYSTEM Execution

CVE Research

Active Campaign Against Triofox: How Attackers Bypassed Setup and Gained SYSTEM Execution

A cyber-espionage group, identified as UNC6485, is actively exploiting a critical vulnerability in Gladinet’s Triofox file-sharing platform. This campaign aims to gain initial network access, steal data, and establish long-term persistence. Attackers are bypassing authentication to create administra...

Apr 28, 2026 • 5 min read

Open Microsoft Tackles 1 Zero-Day and 63 Fixes in November 2025 Patch Tuesday
Microsoft Tackles 1 Zero-Day and 63 Fixes in November 2025 Patch Tuesday

CVE Research

Microsoft Tackles 1 Zero-Day and 63 Fixes in November 2025 Patch Tuesday

It’s that time again – Patch Tuesday is here. This November, Microsoft rolled out fixes for 63 security flaws, featuring one actively exploited zero-day and four Critical vulnerabilities.

Apr 28, 2026 • 4 min read

Open Critical NPM Package Vulnerability Puts AI and NLP Applications at Risk of Exploitation
Critical NPM Package Vulnerability Puts AI and NLP Applications at Risk of Exploitation

CVE Research

Critical NPM Package Vulnerability Puts AI and NLP Applications at Risk of Exploitation

The discovery of CVE-2025-12735 reveals a critical remote code execution (RCE) weakness in the popular JavaScript expression-evaluation library expr-eval. Exploitation allows an attacker who can supply crafted input to influence the parser’s evaluation context and execute arbitrary system-level comm...

Apr 28, 2026 • 3 min read