SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open RDSEED Vulnerability in AMD Zen 5: A Threat to Hardware Randomness Integrity
RDSEED Vulnerability in AMD Zen 5: A Threat to Hardware Randomness Integrity

CVE Research

RDSEED Vulnerability in AMD Zen 5: A Threat to Hardware Randomness Integrity

AMD has confirmed a significant flaw in the RDSEED instruction used for hardware-level random number generation on Zen 5 CPUs. The vulnerability, cataloged as AMD-SB-7055 and assigned CVE-2025-62626, can cause the 16-bit and 32-bit RDSEED variants to return zero instead of genuine entropy, which sof...

Apr 28, 2026 • 4 min read

Open Act Fast! SMB Vulnerability Lets Attackers Gain SYSTEM-Level Access
Act Fast! SMB Vulnerability Lets Attackers Gain SYSTEM-Level Access

CVE Research

Act Fast! SMB Vulnerability Lets Attackers Gain SYSTEM-Level Access

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a high-severity privilege escalation vulnerability in Windows Server Message Block (SMB) that is now being actively exploited in the wild. This vulnerability, tracked as CVE-2025-33073, could allow attackers t...

Apr 28, 2026 • 3 min read

Open Critical RCE Flaw Hits Motex LANSCOPE, CISA Issues Warning
Critical RCE Flaw Hits Motex LANSCOPE, CISA Issues Warning

CVE Research

Critical RCE Flaw Hits Motex LANSCOPE, CISA Issues Warning

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-61932, a critical security flaw in Motex LANSCOPE Endpoint Manager, to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. This vulnerability allows remote attackers to execute a...

Apr 28, 2026 • 3 min read

Open Threat Analysis: Bitter APT Uses C# Implant “cayote.log” in Espionage Operations
Threat Analysis: Bitter APT Uses C# Implant “cayote.log” in Espionage Operations

CVE Research

Threat Analysis: Bitter APT Uses C# Implant “cayote.log” in Espionage Operations

A targeted phishing campaign is exploiting a security flaw, CVE-2025-8088, to attack government, military, and electric power sectors in China and Pakistan. The operation is attributed to the cyber-espionage group Bitter APT. Attackers use phishing emails containing malicious Microsoft Excel or RAR ...

Apr 28, 2026 • 4 min read

Open ToolShell Unlocked: Chinese-Aligned Hackers Weaponize SharePoint Zero-Day for Global Espionage
ToolShell Unlocked: Chinese-Aligned Hackers Weaponize SharePoint Zero-Day for Global Espionage

CVE Research

ToolShell Unlocked: Chinese-Aligned Hackers Weaponize SharePoint Zero-Day for Global Espionage

A critical vulnerability in Microsoft-SharePoint-Server (tracked as CVE-2025-53770 and part of the “ToolShell” chain) has been actively exploited by multiple China-aligned threat actors including Linen-Typhoon, Violet-Typhoon, and Storm-2603. The flaw enables unauthenticated remote code execution an...

Apr 28, 2026 • 6 min read

Open Double Zero-Day Trouble: Microsoft Races to Contain Active Windows Exploits
Double Zero-Day Trouble: Microsoft Races to Contain Active Windows Exploits

CVE Research

Double Zero-Day Trouble: Microsoft Races to Contain Active Windows Exploits

In the ever-evolving landscape of cybersecurity, staying ahead of emerging threats is paramount. This October, Microsoft’s Patch Tuesday addressed a staggering 183 security flaws, a clear indication of the persistent challenges faced by software vendors in safeguarding their products. Among these fi...

Apr 28, 2026 • 3 min read

Open Triple Threat: Dell Storage Manager Flaws Put Systems at Risk
Triple Threat: Dell Storage Manager Flaws Put Systems at Risk

CVE Research

Triple Threat: Dell Storage Manager Flaws Put Systems at Risk

On October 24, 2025, Dell Technologies addressed three critical vulnerabilities in its Storage Manager software. These vulnerabilities could allow an attacker to bypass authentication, expose sensitive data, and gain unauthorized system access.

Apr 28, 2026 • 3 min read

Open ProxyCommand Panic: CVE-2025-61984 Lets Attackers Hijack SSH Clients
ProxyCommand Panic: CVE-2025-61984 Lets Attackers Hijack SSH Clients

CVE Research

ProxyCommand Panic: CVE-2025-61984 Lets Attackers Hijack SSH Clients

A newly discovered vulnerability in OpenSSH’s ProxyCommand feature, identified as CVE-2025-61984, allows remote attackers to execute arbitrary code on client systems. This critical flaw stems from the insufficient filtering of control characters within usernames when the ProxyCommand string is expan...

Apr 28, 2026 • 4 min read

Open Critical XWiki Vulnerability Abused in the Wild for Cryptocurrency Mining
Critical XWiki Vulnerability Abused in the Wild for Cryptocurrency Mining

CVE Research

Critical XWiki Vulnerability Abused in the Wild for Cryptocurrency Mining

A critical remote code execution (RCE) vulnerability (CVE-2025-24893) in XWiki, a widely-used open-source wiki platform, is being actively exploited in the wild. This exploitation leads to the deployment of cryptocurrency mining malware on compromised servers. The vulnerability allows unauthenticate...

Apr 28, 2026 • 3 min read