SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Critical NPM Package Vulnerability Puts AI and NLP Applications at Risk of Exploitation
The discovery of CVE-2025-12735 reveals a critical remote code execution (RCE) weakness in the popular JavaScript expression-evaluation library expr-eval. Exploitation allows an attacker who can supply crafted input to influence the parser’s evaluation context and execute arbitrary system-level comm...

CVE Research
Control Web Panel Breached: Critical RCE Exploited in the Wild
A critical vulnerability has been identified in Control Web Panel (CWP), a widely used web hosting control panel also known as CentOS Web Panel, which is now under active exploitation. The Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding this vulnerability, ident...

CVE Research
QNAP NetBak Exposed: Critical ASP.NET Core Bug Enables Security Bypass
A critical security vulnerability has been identified in QNAP’s NetBak PC Agent software, stemming from a flaw in Microsoft ASP.NET Core. Tracked as CVE-2025-55315, this vulnerability allows attackers to exploit HTTP Request Smuggling techniques, potentially bypassing essential security controls and...

CVE Research
Burning Down the Firewall: Cisco ASA and FTD Under Active Exploitation
Cisco has issued a warning regarding a new wave of attacks targeting their Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software. This new attack variant exploits vulnerabilities CVE-2025-20333 and CVE-2025-20362, potentially leading to denial-of-service (DoS) ...

CVE Research
Chrome Zero-Day Exploited to Deliver Italian Memento Labs’ LeetAgent Spyware
A zero-day vulnerability in Google Chrome, identified as CVE-2025-2783, was recently exploited in the wild to deliver the LeetAgent spyware. This spyware has been linked to the Italian vendor Memento Labs, previously known as Hacking Team. The vulnerability, a sandbox escape, allowed attackers to by...

CVE Research
Patch Now! Apache Tomcat Vulnerabilities Expose Servers to RCE Risk
The Apache Software Foundation recently addressed two security vulnerabilities affecting multiple versions of Apache Tomcat, a widely-used open-source Java servlet container. These vulnerabilities, identified as CVE-2025-55752 and CVE-2025-55754, impact versions 9, 10, and 11 of Apache Tomcat and hi...

CVE Research
Chrome 142 Released: High-Severity V8 Flaws Fixed, $100K in Rewards Paid
Google has released Chrome 142, addressing a total of 20 security flaws, including two high-severity vulnerabilities affecting the V8 JavaScript engine. The company awarded a total of $100,000 in bug bounties to researchers who reported these critical issues.

CVE Research
BadCandy: Stealth Implant Converts IOS XE into a Persistent Surveillance Node
Cybercriminals and advanced persistent threat (APT) actors continue to evolve toward stealthier, persistence-focused, and profit-driven operations. Recent intelligence reports reveal a coordinated exploitation campaign combining high-severity vulnerabilities—the Cisco IOS XE privilege escalation fla...

