SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
SonicWall Fixes Actively Exploited SMA 100 Vulnerability Used in Overstep Attacks
A critical zero-day flaw in SonicWall SMA 100 VPN appliances is being leveraged in the wild to distribute Overstep, a stealth malware capable of maintaining persistent access, stealing credentials, and executing lateral attacks. The vulnerability allows remote code execution without authentication, ...

CVE Research
Inside UNC5221’s BRICKSTORM: Unmasking a Stealthy Espionage Backdoor
Since at least early 2025, a suspected China-nexus cluster, tracked as UNC5221, has deployed the BRICKSTORM backdoor using the vulnerabilities CVE-2023-46805 and CVE-2024-21887 to establish long-term, stealthy access to high-value targets, notably legal services, SaaS providers, BPOs, and technology...

CVE Research
Versa Director Zero-Day Under Siege: Volt Typhoon and Bronze Silhouette Campaign
Cybercriminal groups and nation aligned advanced persistent threats (APTs) are increasingly converging on stealth first, persistence focused, and monetization driven operations. Recent reporting shows both financially motivated actors and suspected state aligned groups actively exploiting a critical...

CVE Research
CISA Issues Emergency Directive as Cisco ASA Zero-Day Exploited in the Wild
Cisco has issued an urgent security advisory, urging customers to patch two critical zero-day vulnerabilities affecting the VPN web server components of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. These flaws are actively ...

CVE Research
Microsoft Open Management Infrastructure (OMI) Critical Vulnerabilities Under Active Exploitation – OMIGOD
Microsoft Open Management Infrastructure (OMI) is an open-source project which allows users to manage configurations across remote and local environments and collect statistics. The primary goal of OMI is to provide a rich, high-performance, standard-based management stack that is suitable for a wid...

CVE Research
Cisco Issues Urgent Warning on Exploited IOS Zero-Day Vulnerability
The disclosure of a high-severity zero-day vulnerability in Cisco IOS and IOS XE Software exposes a critical weakness in the Simple Network Management Protocol (SNMP) subsystem. Tracked as CVE-2025-20352, the flaw is already being actively exploited in the wild, placing countless organizations at im...

CVE Research
Automating Endpoint Management: Best Practices for IT Teams
Every organization in the world relies on laptops, mobile devices, servers, and IoT equipment. Each device provides business applications and but also might hold sensitive data, which can pose a potential risk if left unmanaged. Manually checking and managing these endpoints is practically impossibl...

CVE Research
Firewall on Fire: Critical CVE-2025-9242 Hits WatchGuard Firebox
WatchGuard has issued urgent security updates to address a critical vulnerability, CVE-2025-9242, affecting its Firebox firewalls. This high-severity flaw could allow a remote, unauthenticated attacker to execute arbitrary code on vulnerable devices, potentially leading to complete system compromise...

