SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
HTTP/1.1 Vulnerability: A Looming Threat to Millions of Websites
A fundamental vulnerability within the HTTP/1.1 protocol poses a significant threat to millions of websites, potentially allowing attackers to execute hostile takeovers through sophisticated request smuggling attacks. This flaw, rooted in the protocol’s design, creates ambiguity in request boundarie...

CVE Research
15000 Jenkins Servers Exposed to Unauthenticated RCE Attack
A recently identified command injection vulnerability, CVE-2025-53652, in the Jenkins Git Parameter plugin puts approximately 15,000 Jenkins servers at risk of remote code execution (RCE). This flaw could allow attackers to compromise unauthenticated Jenkins servers, potentially leading to significa...

CVE Research
Retbleed Reloaded: New Exploit Pierces CPU Memory Defenses
Security researchers have recently demonstrated a significantly improved exploit for the Retbleed CPU vulnerability, highlighting the ongoing risks posed by speculative execution flaws in modern processors. This exploit allows attackers to read arbitrary memory from affected systems, bypassing secur...

CVE Research
UAC-0099’s New Weapon: The WinRAR Exploit You Can’t Ignore
A critical vulnerability in WinRAR, identified as CVE-2023-38831, is being actively exploited by threat actors to execute arbitrary code on a victim’s machine. This flaw allows attackers to craft malicious ZIP archives that can deliver malware when a user attempts to view a seemingly benign file. Th...

CVE Research
Espionage in Plain Sight: Telecoms Breached by CL-STA-0969 Group
China-nexus espionage group, tracked as CL-STA-0969 and overlapping with “Liminal Panda,” is actively targeting telecommunications organizations in Asia. This sophisticated campaign, observed between February and November 2024, leverages brute-force attacks for initial access, followed by the exploi...

CVE Research
Joint Threat to Safari and Chrome Users – Patch CVE-2025-6558 Now
Apple has rolled out critical security updates across its platforms to address a high-severity vulnerability in the WebKit engine. This flaw, tracked as CVE-2025-6558, was exploited as a zero-day in Google Chrome and could potentially impact Safari and other Apple applications relying on WebKit. The...

CVE Research
Hackers Weaponize SharePoint 0-Day: Widespread Exploitation Ongoing
A critical zero-day vulnerability chain, called “ToolShell,” is actively exploited in Microsoft SharePoint Server on-premises environments. This sophisticated attack vector leverages vulnerabilities to achieve unauthenticated remote code execution (RCE), bypass multi-factor authentication, and enabl...

CVE Research
Microsoft Uncovers Sploitlight: How a Spotlight Plugin Flaw Evades macOS TCC Protections
Microsoft Threat Intelligence recently disclosed a serious macOS vulnerability dubbed Sploitlight. It tracked as CVE-2025-31199 that leverages Spotlight importer plugins to bypass Apple’s Transparency, Consent, and Control (TCC) framework and exfiltrate files normally off-limits, including Apple Int...

CVE Research
Hackers Beware: Dell Laptop Firmware Vulnerabilities Put Credentials at Risk
A firmware-level security nightmare is unfolding across millions of Dell laptops worldwide. The devices trusted by government agencies, cybersecurity professionals, and enterprise organizations to protect their most sensitive data are now vulnerable to a sophisticated attack vector that could render...
