SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open How the TP-Link 0-Day Bypasses ASLR: A Technical Post-Mortem
How the TP-Link 0-Day Bypasses ASLR: A Technical Post-Mortem

CVE Research

How the TP-Link 0-Day Bypasses ASLR: A Technical Post-Mortem

A critical zero-day remote code execution (RCE) vulnerability, identified as CVE-2025-9961, with CVSS and EPSS scores of 8.6 and 0.10% respectively, has been discovered in TP-Link routers. Security researchers have released a proof-of-concept (PoC) exploit, demonstrating how attackers can bypass Add...

Apr 28, 2026 • 3 min read

Open Worm in the Code: npm Supply Chain Attack Compromises 40+ Packages
Worm in the Code: npm Supply Chain Attack Compromises 40+ Packages

CVE Research

Worm in the Code: npm Supply Chain Attack Compromises 40+ Packages

A major supply chain attack has been uncovered in the npm ecosystem, where more than 40 widely used packages were found compromised. The campaign, powered by a self-replicating malware dubbed “Shai-Hulud”, is actively spreading and exfiltrating sensitive credentials. Developers and organizations usi...

Apr 28, 2026 • 3 min read

Open From License to Root: Critical Flaw in Fortra GoAnywhere MFT
From License to Root: Critical Flaw in Fortra GoAnywhere MFT

CVE Research

From License to Root: Critical Flaw in Fortra GoAnywhere MFT

A critical vulnerability has been identified in Fortra’s GoAnywhere Managed File Transfer (MFT) platform, posing a significant risk to organizations that rely on this software for secure file exchange. The flaw, identified as CVE-2025-10035, has been assigned a CVSS score of 10.0, the highest possib...

Apr 28, 2026 • 4 min read

Open Linux CUPS: Remote DoS and Authentication Bypass Exploit
Linux CUPS: Remote DoS and Authentication Bypass Exploit

CVE Research

Linux CUPS: Remote DoS and Authentication Bypass Exploit

The discovery of CVE-2025-58364 and CVE-2025-58060 reveals two critical weaknesses in the Linux Common Unix Printing System (CUPS). Exploiting these vulnerabilities could enable remote denial-of-service and authentication bypass attacks, endangering millions of systems that rely on CUPS as a fundame...

Apr 28, 2026 • 3 min read

Open Remediation Rollback in Saner Cloud Makes Prevention Practical

Remediation Rollback in Saner Cloud Makes Prevention Practical

CVE Research

Remediation Rollback in Saner Cloud Makes Prevention Practical

Security teams move fast when they know a change is reversible. Remediation Rollback in SecPod’s Saner Cloud gives your team that safety net, so you can fix risky configurations without hesitation, keep production steady, and block attack paths before they’re exploited. Pair that with continuous vis...

Apr 28, 2026 • 5 min read

Open Critical Google Chrome Security Update: Patches For Remote Code Execution Vulnerabilities
google chrome updates browser to fix critical remote code flaws

CVE Research

Critical Google Chrome Security Update: Patches For Remote Code Execution Vulnerabilities

Google has released an urgent security update for the Chrome browser across Windows, Mac, and Linux platforms to address critical vulnerabilities that could enable remote attackers to execute arbitrary code.

Apr 28, 2026 • 3 min read

Open Critical SessionReaper Flaw in Adobe Commerce Puts Customer Accounts at Risk
Critical SessionReaper Flaw in Adobe Commerce Puts Customer Accounts at Risk

CVE Research

Critical SessionReaper Flaw in Adobe Commerce Puts Customer Accounts at Risk

A critical vulnerability, CVE-2025-54236, dubbed “SessionReaper,” has been identified in Adobe Commerce and Magento Open Source platforms, potentially allowing attackers to seize control of customer accounts. The severity of this flaw has prompted Adobe to release an emergency patch outside of its r...

Apr 28, 2026 • 4 min read

Open Deserialization Derailment: Dassault’s DELMIA Flaw Goes Live
Deserialization Derailment: Dassault’s DELMIA Flaw Goes Live

CVE Research

Deserialization Derailment: Dassault’s DELMIA Flaw Goes Live

DELMIA Apriso is utilized in production processes for digitalization and monitoring, with widespread deployment in automotive, aerospace, electronics, high-tech, and industrial machinery divisions. It supports various functions, including production scheduling, quality management, resource allocatio...

Apr 28, 2026 • 3 min read

Open WeepSteel Rises: Attackers Exploit Critical Sitecore Deserialization Bug
WeepSteel Rises: Attackers Exploit Critical Sitecore Deserialization Bug

CVE Research

WeepSteel Rises: Attackers Exploit Critical Sitecore Deserialization Bug

A critical zero-day vulnerability in Sitecore, tracked as CVE-2025-53690, has been exploited in the wild to deploy the WeepSteel backdoor. This flaw, an insecure deserialization issue, allows attackers to craft malicious ViewState payloads using default or sample ASP.NET machineKey values. Exploitat...

Apr 28, 2026 • 5 min read