SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Patch Now: CVE-2021-43226 Windows Vulnerability Actively Exploited
Patch Now: CVE-2021-43226 Windows Vulnerability Actively Exploited

CVE Research

Patch Now: CVE-2021-43226 Windows Vulnerability Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a privilege escalation vulnerability in Microsoft Windows, identified as CVE-2021-43226. This vulnerability resides within the Common Log File System (CLFS) driver and is being lever...

Apr 28, 2026 • 3 min read

Open Operation Zero Disco: Exploitation of Cisco SNMP Vulnerability for Rootkit Deployment
Operation Zero Disco: Exploitation of Cisco SNMP Vulnerability for Rootkit Deployment

CVE Research

Operation Zero Disco: Exploitation of Cisco SNMP Vulnerability for Rootkit Deployment

Apr 28, 2026 • 6 min read

Open AgeLocker Ransomware Targeting QNAP NAS Devices
AgeLocker Ransomware Targeting QNAP NAS Devices

CVE Research

AgeLocker Ransomware Targeting QNAP NAS Devices

AgeLocker Ransomware targeting QNAP network-attached storage (NAS) devices have been used by attackers to encrypt user data and demand a ransom. It has been found after research that no unpatched vulnerability was found to be exploited in the use of AgeLocker ransomware attack, whereas all the known...

Apr 28, 2026 • 2 min read

Open QNAP Patches Critical Vulnerabilities in NAS Appliances
QNAP Patches Critical Vulnerabilities in NAS Appliances

CVE Research

QNAP Patches Critical Vulnerabilities in NAS Appliances

QNAP addresses multiple vulnerabilities in its product line affecting Surveillance Station and Photo Station applications using a vulnerability management tool. These vulnerable software applications are powered by Network Attached Storage (NAS), a storage management technology powering file sharing...

Apr 28, 2026 • 2 min read

Open UNC1945 Infiltrates Corporate Networks through a Solaris Zero-Day Bug
UNC1945 Infiltrates Corporate Networks through a Solaris Zero-Day Bug

CVE Research

UNC1945 Infiltrates Corporate Networks through a Solaris Zero-Day Bug

A new zero-day vulnerability  (CVE-2020-14871) in Oracle Solaris has been brought to light by the FireEye security research team, Mandiant. Moreover, the vulnerability has been reported as being actively exploited. A Vulnerability Management System can resolve these issues. Hence, the sophisticated ...

Apr 28, 2026 • 3 min read

Open Critical Zero-Day Flaw Actively Exploited in WordPress Fancy Product Designer Plugin
Critical Zero-Day Flaw Actively Exploited in WordPress Fancy Product Designer Plugin

CVE Research

Critical Zero-Day Flaw Actively Exploited in WordPress Fancy Product Designer Plugin

A critical zero-day vulnerability has been discovered in a WordPress plugin called Fancy Product Designer. A Wordfence Threat Intelligence team from WordPress security company Defiant alerted about this vulnerability. The vulnerability is under active attack, which is tracked as CVE-2021-24370 by us...

Apr 28, 2026 • 3 min read

Open FortiDDoS Appliances Vulnerable to OS Command Injection, Urges Immediate Patching
FortiDDoS Appliances Vulnerable to OS Command Injection, Urges Immediate Patching

CVE Research

FortiDDoS Appliances Vulnerable to OS Command Injection, Urges Immediate Patching

Fortinet has recently addressed a medium-severity OS command injection vulnerability, CVE-2024-45325, in its FortiDDoS-F appliances. This flaw could allow a privileged attacker to execute unauthorized commands via the command-line interface (CLI). Given the critical role FortiDDoS-F appliances play ...

Apr 28, 2026 • 3 min read

Open SCAP Feed Release – Part 1 : 13-Apr-2017

SCAP Feed Release – Part 1 : 13-Apr-2017

CVE Research

SCAP Feed Release – Part 1 : 13-Apr-2017

The following SCAP content has been released to SCAP Repo and SecPod Saner solution. SecPod Saner will automatically pull the relevant content on its next scheduled update.

Apr 28, 2026 • 5 min read

Open Qsnatch snatching credentials in an ongoing Campaign

Qsnatch snatching credentials in an ongoing Campaign

CVE Research

Qsnatch snatching credentials in an ongoing Campaign

QSnatch, the new malware in town has already affected thousands of devices and wouldn’t call it quits. This malware was first discovered in October 2019 by the National Cyber Security Center of Finland (NCSC-FI) after it received reports via the Autoreporter service indicating the communication of i...

Apr 28, 2026 • 2 min read