SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open BIND 9 Cache Poisoning Flaws Pose High Risk to DNS Reliability — CVE-2025-40778, CVE-2025-40780
BIND 9 Cache Poisoning Flaws Pose High Risk to DNS Reliability — CVE-2025-40778, CVE-2025-40780

CVE Research

BIND 9 Cache Poisoning Flaws Pose High Risk to DNS Reliability — CVE-2025-40778, CVE-2025-40780

On October 22, 2025, the Internet Systems Consortium (ISC) disclosed multiple vulnerabilities in BIND 9, the world’s most widely used DNS software. Among these, CVE-2025-40778 and CVE-2025-40780 present high-severity cache poisoning risks, while CVE-2025-8677 introduces a high-severity denial-of-ser...

Apr 28, 2026 • 3 min read

Open Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento
Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento

CVE Research

Urgent: Critical SessionTakeover Flaw (CVE-2025-54236) in Adobe Commerce & Magento

A critical vulnerability, CVE-2025-54236, dubbed SessionReaper, is currently under active exploitation in Adobe Commerce and Magento Open-Source platforms. The flaw arises from improper input validation and can lead to customer account takeover and remote code execution. Security firm Sansec has rep...

Apr 28, 2026 • 3 min read

Open CVE-2025-61884: Unauthenticated Data Exposure in Oracle E-Business Suite
CVE-2025-61884: Unauthenticated Data Exposure in Oracle E-Business Suite

CVE Research

CVE-2025-61884: Unauthenticated Data Exposure in Oracle E-Business Suite

Oracle has released an urgent Security Alert Advisory addressing a critical vulnerability in Oracle E-Business Suite, identified as CVE-2025-61884. This flaw enables remote attackers to access sensitive data or resources without requiring authentication.

Apr 28, 2026 • 3 min read

Open Adobe AEM’s Debug Doorway: Critical RCE Under Active Exploitation
Adobe AEM’s Debug Doorway: Critical RCE Under Active Exploitation

CVE Research

Adobe AEM’s Debug Doorway: Critical RCE Under Active Exploitation

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw affecting Adobe Experience Manager (AEM) to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. The vulnerability, CVE-2025-54253, has a CVSS score of 10.0, representing maxi...

Apr 28, 2026 • 2 min read

Open Technical Breakdown: How the ArcaneDoor Group Leverages Multiple Cisco Zero-Days for Stealthy Infiltration
Technical Breakdown: How the ArcaneDoor Group Leverages Multiple Cisco Zero-Days for Stealthy Infiltration

CVE Research

Technical Breakdown: How the ArcaneDoor Group Leverages Multiple Cisco Zero-Days for Stealthy Infiltration

A sophisticated, state-sponsored threat actor tracked as ArcaneDoor is actively exploiting two new zero-day vulnerabilities in Cisco firewalls. The campaign deploys a dangerous malware cocktail to conduct espionage against government networks.

Apr 28, 2026 • 4 min read

Open CVE-2025-61882: Why Clop’s Latest Oracle EBS Strike Should Scare You
CVE-2025-61882: Why Clop’s Latest Oracle EBS Strike Should Scare You

CVE Research

CVE-2025-61882: Why Clop’s Latest Oracle EBS Strike Should Scare You

Oracle E-Business Suite (EBS), a comprehensive suite of enterprise resource planning (ERP) applications, is integral to managing core business operations for numerous organizations worldwide. It handles critical functions across finance, HR, and supply chain management.

Apr 28, 2026 • 4 min read

Open Under Medusa’s Gaze: GoAnywhere Zero-Day Powers Ransomware Attacks
Under Medusa’s Gaze: GoAnywhere Zero-Day Powers Ransomware Attacks

CVE Research

Under Medusa’s Gaze: GoAnywhere Zero-Day Powers Ransomware Attacks

A critical deserialization vulnerability in Fortra GoAnywhere MFT (CVE-2025-10035 , with a CVSS score of 10.0) has been actively exploited by a Medusa ransomware affiliate tracked as Storm-1175 to gain unauthenticated remote code execution against internet-exposed Admin Consoles. Operators exploited...

Apr 28, 2026 • 8 min read

Open China-Linked APT Exploits VMware Zero-Day Vulnerability Active Since October 2024
China-Linked APT Exploits VMware Zero-Day Vulnerability Active Since October 2024

CVE Research

China-Linked APT Exploits VMware Zero-Day Vulnerability Active Since October 2024

A newly discovered and actively exploited local privilege escalation vulnerability in VMware Tools and Aria Operations, tracked as CVE-2025-41244, has been leveraged as a zero-day since mid-October 2024. The exploitation has been attributed to UNC5174, a China-linked advanced persistent threat (APT)...

Apr 28, 2026 • 4 min read

Open Zimbra Zero-Day Exploitation Vector: Malicious ICS Files Targeting Brazil’s Military
Zimbra Zero-Day Exploitation Vector: Malicious ICS Files Targeting Brazil’s Military

CVE Research

Zimbra Zero-Day Exploitation Vector: Malicious ICS Files Targeting Brazil’s Military

The discovery and exploitation of CVE-2025-27915, a stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS), underscores the persistent threat posed by input sanitization flaws in widely used enterprise software. This now-patched zero-day vulnerability was actively exploi...

Apr 28, 2026 • 4 min read