SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Paper Werewolf Group Exploits WinRAR Zero-Day to Spread Malware
Paper Werewolf Group Exploits WinRAR Zero-Day to Spread Malware

CVE Research

Paper Werewolf Group Exploits WinRAR Zero-Day to Spread Malware

The cyber-espionage group Paper Werewolf (also identified as GOFFEE) is exploiting a zero-day flaw in WinRAR to target Russian entities. The campaign relies on phishing emails and weaponized archive files to evade defenses and deliver malware, underscoring the need for timely patching and proactive ...

Apr 28, 2026 • 3 min read

Open New Microsoft Exchange Server Vulnerability Allows Privilege Escalation to Admin
New Microsoft Exchange Server Vulnerability Allows Privilege Escalation to Admin

CVE Research

New Microsoft Exchange Server Vulnerability Allows Privilege Escalation to Admin

A significant security flaw, CVE-2025-53786, has been discovered in Microsoft Exchange Server hybrid environments. This flaw could enable attackers with on-premises administrative privileges to escalate their access within connected cloud systems. Publicly disclosed on August 6, 2025, the vulnerabil...

Apr 28, 2026 • 5 min read

Open Critical Chrome Update: Patch CVE-2025-9478 Before Attackers Strike
Critical Chrome Update: Patch CVE-2025-9478 Before Attackers Strike

CVE Research

Critical Chrome Update: Patch CVE-2025-9478 Before Attackers Strike

A critical security update has been released for the Chrome Stable channel to address a use-after-free vulnerability in the ANGLE graphics library. This flaw, identified as CVE-2025-9478, could allow attackers to execute arbitrary code on vulnerable systems.

Apr 28, 2026 • 2 min read

Open Squid Proxy Under Threat: Critical Bug Enables Remote Code Execution
Squid Proxy Under Threat: Critical Bug Enables Remote Code Execution

CVE Research

Squid Proxy Under Threat: Critical Bug Enables Remote Code Execution

A critical vulnerability has been discovered in the Squid Web Proxy server, which could allow remote attackers to execute arbitrary code on affected systems. This vulnerability affects multiple versions and may impact many systems relying on Squid for caching and proxy functionality.

Apr 28, 2026 • 3 min read

Open 5 Signs You Have a Visibility Gap – And Why A Prevention-First Philosophy Is The Only Remedy
5 Signs You Have a Visibility Gap – And Why A Prevention-First Philosophy Is The Only Remedy

CVE Research

5 Signs You Have a Visibility Gap – And Why A Prevention-First Philosophy Is The Only Remedy

The cybersecurity industry of today has matured tools for discovery and detection – what it has not institutionalized at scale is closure. Modern security programs can show long lists of vulnerabilities, misconfigurations, policy violations and alerts – and still be vulnerable. Attackers succeed not...

Apr 28, 2026 • 8 min read

Open Virtual Environments Under Fire: Fire Ant Campaign Breaches VMware Systems
Virtual Environments Under Fire: Fire Ant Campaign Breaches VMware Systems

CVE Research

Virtual Environments Under Fire: Fire Ant Campaign Breaches VMware Systems

A threat actor, codenamed Fire Ant, has targeted virtualization and networking infrastructure as part of a prolonged cyber-espionage campaign uncovered in 2025. The attackers focused on exploiting vulnerabilities and abusing trusted management tools to gain persistent, hypervisor-level access across...

Apr 28, 2026 • 4 min read

Open New MadeYouReset Exploit Bypasses HTTP/2 DoS Protections
New MadeYouReset Exploit Bypasses HTTP/2 DoS Protections

CVE Research

New MadeYouReset Exploit Bypasses HTTP/2 DoS Protections

A novel attack technique named MadeYouReset has been discovered, targeting multiple implementations of the HTTP/2 protocol. This flaw, sitting at a comfortable 7.5 on the CVSS scale, allows attackers to bypass existing mitigations and launch significant denial-of-service (DoS) attacks. The vulnerabi...

Apr 28, 2026 • 4 min read

Open Stealth in the Storm! Breaking Down Salt Typhoon’s Global Cyber Campaign
Stealth in the Storm! Breaking Down Salt Typhoon’s Global Cyber Campaign

CVE Research

Stealth in the Storm! Breaking Down Salt Typhoon’s Global Cyber Campaign

Salt Typhoon, a China-linked advanced persistent threat (APT) group, has been conducting a persistent cyber-espionage campaign since at least 2019. The group targets telecommunications providers, government agencies, transportation, lodging, and military infrastructure worldwide, exploiting vulnerab...

Apr 28, 2026 • 6 min read

Open Gayfemboy Malware Emerges: Next-Gen Mirai Variant Targets Cisco and TP-Link Routers
Gayfemboy Malware Emerges: Next-Gen Mirai Variant Targets Cisco and TP-Link Routers

CVE Research

Gayfemboy Malware Emerges: Next-Gen Mirai Variant Targets Cisco and TP-Link Routers

FortiGuard Labs has uncovered a new malware strain dubbed Gayfemboy, a Mirai successor that aggressively targets routers and critical networking gear from Cisco, TP-Link, DrayTek, and Raisecom. The campaign exploits multiple CVEs to compromise infrastructure devices, establish long-term persistence,...

Apr 28, 2026 • 5 min read