SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
BIND 9 Cache Poisoning Flaws Pose High Risk to DNS Reliability — CVE-2025-40778, CVE-2025-40780
On October 22, 2025, the Internet Systems Consortium (ISC) disclosed multiple vulnerabilities in BIND 9, the world’s most widely used DNS software. Among these, CVE-2025-40778 and CVE-2025-40780 present high-severity cache poisoning risks, while CVE-2025-8677 introduces a high-severity denial-of-ser...

CVE Research
Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento
A critical vulnerability, CVE-2025-54236, dubbed SessionReaper, is currently under active exploitation in Adobe Commerce and Magento Open-Source platforms. The flaw arises from improper input validation and can lead to customer account takeover and remote code execution. Security firm Sansec has rep...

CVE Research
CVE-2025-61884: Unauthenticated Data Exposure in Oracle E-Business Suite
Oracle has released an urgent Security Alert Advisory addressing a critical vulnerability in Oracle E-Business Suite, identified as CVE-2025-61884. This flaw enables remote attackers to access sensitive data or resources without requiring authentication.

CVE Research
Adobe AEM’s Debug Doorway: Critical RCE Under Active Exploitation
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw affecting Adobe Experience Manager (AEM) to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. The vulnerability, CVE-2025-54253, has a CVSS score of 10.0, representing maxi...

CVE Research
Technical Breakdown: How the ArcaneDoor Group Leverages Multiple Cisco Zero-Days for Stealthy Infiltration
A sophisticated, state-sponsored threat actor tracked as ArcaneDoor is actively exploiting two new zero-day vulnerabilities in Cisco firewalls. The campaign deploys a dangerous malware cocktail to conduct espionage against government networks.

CVE Research
CVE-2025-61882: Why Clop’s Latest Oracle EBS Strike Should Scare You
Oracle E-Business Suite (EBS), a comprehensive suite of enterprise resource planning (ERP) applications, is integral to managing core business operations for numerous organizations worldwide. It handles critical functions across finance, HR, and supply chain management.

CVE Research
Under Medusa’s Gaze: GoAnywhere Zero-Day Powers Ransomware Attacks
A critical deserialization vulnerability in Fortra GoAnywhere MFT (CVE-2025-10035 , with a CVSS score of 10.0) has been actively exploited by a Medusa ransomware affiliate tracked as Storm-1175 to gain unauthenticated remote code execution against internet-exposed Admin Consoles. Operators exploited...

CVE Research
China-Linked APT Exploits VMware Zero-Day Vulnerability Active Since October 2024
A newly discovered and actively exploited local privilege escalation vulnerability in VMware Tools and Aria Operations, tracked as CVE-2025-41244, has been leveraged as a zero-day since mid-October 2024. The exploitation has been attributed to UNC5174, a China-linked advanced persistent threat (APT)...

CVE Research
Zimbra Zero-Day Exploitation Vector: Malicious ICS Files Targeting Brazil’s Military
The discovery and exploitation of CVE-2025-27915, a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS), underscores the persistent threat posed by input sanitization flaws in widely used enterprise software. This now-patched zero-day vulnerability was actively exploi...
