SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Act Now: Cisco FMC RADIUS Flaw Allows Unauthenticated Remote Code Execution
Act Now: Cisco FMC RADIUS Flaw Allows Unauthenticated Remote Code Execution

CVE Research

Act Now: Cisco FMC RADIUS Flaw Allows Unauthenticated Remote Code Execution

Cisco has recently addressed a critical security vulnerability, CVE-2025-20265, in its Secure Firewall Management Center (FMC) Software. With a maximum CVSS score of 10.0, this flaw poses a significant risk, potentially allowing unauthenticated, remote attackers to execute arbitrary shell commands o...

Apr 28, 2026 • 3 min read

Open Auto-Color Backdoor Weaponizes SAP Flaw for Stealthy Access
Auto-Color Backdoor Weaponizes SAP Flaw for Stealthy Access

CVE Research

Auto-Color Backdoor Weaponizes SAP Flaw for Stealthy Access

A critical zero-day vulnerability in SAP NetWeaver, CVE-2025-31324, is being exploited to deliver “Auto-Color,” a stealthy Linux backdoor. The vulnerability allows for unauthenticated remote code execution (RCE), enabling attackers to achieve full system compromise. Multiple threat actors, including...

Apr 28, 2026 • 6 min read

Open 107 Flaws Fixed, One Zero Day In Microsoft’s August 2025 Patch Tuesday
107 Flaws Fixed, One Zero Day In Microsoft’s August 2025 Patch Tuesday

CVE Research

107 Flaws Fixed, One Zero Day In Microsoft’s August 2025 Patch Tuesday

August’s Patch Tuesday has arrived! This month, Microsoft has released patches for 107 flaws, including 13 critical bugs and one zero-day.

Apr 28, 2026 • 4 min read

Open Data leak: the key business risk posed by CVE-2017-8529
Data leak: the key business risk posed by CVE-2017-8529

CVE Research

Data leak: the key business risk posed by CVE-2017-8529

Information disclosure vulnerabilities are known to cause data confidentiality to be lost. One such vulnerability is CVE-2017-8529, found in Microsoft Internet Explorer can expose sensitive browser data.

Apr 28, 2026 • 3 min read

Open Ivanti EPM Under Fire: How Attackers Can Steal Credentials and Access Your Data
Ivanti EPM Under Fire: How Attackers Can Steal Credentials and Access Your Data

CVE Research

Ivanti EPM Under Fire: How Attackers Can Steal Credentials and Access Your Data

Ivanti has recently addressed three high-severity vulnerabilities in its Endpoint Manager (EPM) software. These flaws could allow attackers to decrypt other users’ passwords or access sensitive database information if exploited. This blog post provides a detailed overview of these vulnerabilities an...

Apr 28, 2026 • 4 min read

Open Dangerous Linux Kernel Exploit Targets Chrome Users for Full Control
Dangerous Linux Kernel Exploit Targets Chrome Users for Full Control

CVE Research

Dangerous Linux Kernel Exploit Targets Chrome Users for Full Control

Executive SummaryA critical vulnerability in the Linux kernel, identified as CVE-2025-38236, enables attackers to escalate privileges from the Chrome renderer sandbox to full kernel-level control on affected Linux systems. Immediate patching is essential, as successful exploitation grants attackers...

Apr 28, 2026 • 3 min read

Open Privileged Path Hijack: Eye Security Exposes Root-Level Vulnerability in Copilot Enterprise
Privileged Path Hijack: Eye Security Exposes Root-Level Vulnerability in Copilot Enterprise

CVE Research

Privileged Path Hijack: Eye Security Exposes Root-Level Vulnerability in Copilot Enterprise

SummaryOn April 18, 2025, Eye Security researchers identified a critical privilege escalation issue in Microsoft Copilot Enterprise’s live Python sandbox (Jupyter Notebook–based). A misconfigured entrypoint script (keepAliveJupyterSvc.sh) ran pgrep without using a full path. Because the $PATH Priori...

Apr 28, 2026 • 4 min read

Open Ghost Calls: Stealthy C2 Attack Exploits Zoom, Teams, and Meet
Ghost Calls: Stealthy C2 Attack Exploits Zoom, Teams, and Meet

CVE Research

Ghost Calls: Stealthy C2 Attack Exploits Zoom, Teams, and Meet

A novel attack technique dubbed “Ghost Calls” has emerged, exploiting web conferencing platforms like Zoom, Microsoft Teams, and Google Meet to create covert command and control (C2) channels. This sophisticated method allows attackers to bypass traditional network security measures, making it a sig...

Apr 28, 2026 • 3 min read

Open Zero Trust Under Fire: Critical Flaws Expose Check Point, Zscaler, and Netskope Users
Zero Trust Under Fire: Critical Flaws Expose Check Point, Zscaler, and Netskope Users

CVE Research

Zero Trust Under Fire: Critical Flaws Expose Check Point, Zscaler, and Netskope Users

Security researchers have uncovered critical vulnerabilities in leading Zero Trust Network Access (ZTNA) solutions from major cybersecurity vendors, including Zscaler, Netskope, and Check Point. These findings, presented at DEF CON 33 in Las Vegas, highlight potential authentication bypasses, privil...

Apr 28, 2026 • 4 min read