SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open 378 Vulnerabilities Fixed in Oracle’s Latest Critical Patch Update
378 Vulnerabilities Fixed in Oracle’s Latest Critical Patch Update

CVE Research

378 Vulnerabilities Fixed in Oracle’s Latest Critical Patch Update

Oracle’s quarterly critical patch update made its entrance with a bang this April, fixing 378 vulnerabilities in both Oracle and third-party product families. Oracle Communications accounted for the highest number of flaws, totaling 103, with Oracle MySQL and Oracle Communications Applications trail...

Apr 28, 2026 • 5 min read

Open 137 Flaws Fixed, One Zero Day In Microsoft’s July 2025 Patch Tuesday
137 Flaws Fixed, One Zero Day In Microsoft’s July 2025 Patch Tuesday

CVE Research

137 Flaws Fixed, One Zero Day In Microsoft’s July 2025 Patch Tuesday

It’s time for another Patch Tuesday! This month, Microsoft has released patches for 137 flaws, including 14 critical bugs and one zero-day.

Apr 28, 2026 • 4 min read

Open NTLM Hijack: DNN Users Urged to Patch Critical Unicode Flaw
NTLM Hijack: DNN Users Urged to Patch Critical Unicode Flaw

CVE Research

NTLM Hijack: DNN Users Urged to Patch Critical Unicode Flaw

DotNetNuke (DNN), a widely used open-source content management system (CMS) built on the .NET framework, has a critical vulnerability. This flaw, CVE-2025-52488, allows attackers to hijack NTLM through a Unicode normalization bypass. This can lead to the theft of sensitive credentials, potentially c...

Apr 28, 2026 • 4 min read

Open Surface Protection Fails in the Cloud: Why Deep Workload Defense Is Now Mandatory
Surface Protection Fails in the Cloud: Why Deep Workload Defense Is Now Mandatory

CVE Research

Surface Protection Fails in the Cloud: Why Deep Workload Defense Is Now Mandatory

Many cloud security tools still focus on scanning images, enforcing perimeter controls, or detecting simple misconfigurations. Attackers bypass these defenses by exploiting deep workload issues — stale dependencies, excessive permissions, or unpatched runtime services. IBM’s XForce Threat Intelligen...

Apr 28, 2026 • 8 min read

Open Bypassing Secure Boot: A Linux Initramfs Vulnerability (CVE-2016-4484)
Bypassing Secure Boot: A Linux Initramfs Vulnerability (CVE-2016-4484)

CVE Research

Bypassing Secure Boot: A Linux Initramfs Vulnerability (CVE-2016-4484)

Modern Linux systems implement layers of security, including Secure Boot, full-disk encryption, and bootloader passwords. However, a long-standing vulnerability in the Linux boot process—CVE-2016-4484—exposes a critical gap that allows attackers to bypass these protections by abusing the initramfs (...

Apr 28, 2026 • 4 min read

Open CISA Issues Warning: Ongoing Attacks Exploiting Ruby on Rails Path Traversal Bug
CISA Issues Warning: Ongoing Attacks Exploiting Ruby on Rails Path Traversal Bug

CVE Research

CISA Issues Warning: Ongoing Attacks Exploiting Ruby on Rails Path Traversal Bug

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about an actively exploited path traversal vulnerability in the Ruby on Rails framework. Tracked as CVE-2019-5418, this flaw allows attackers to access arbitrary files on target servers. Given the active exploi...

Apr 28, 2026 • 3 min read

Open ClamAV 1.4.3 and 1.0.9 Released: Addressing Critical RCE Vulnerability
ClamAV 1.4.3 and 1.0.9 Released: Addressing Critical RCE Vulnerability

CVE Research

ClamAV 1.4.3 and 1.0.9 Released: Addressing Critical RCE Vulnerability

The ClamAV team has released versions 1.4.3 and 1.0.9, critical security patches that address CVE-2025-20260 vulnerabilities that could compromise system security. These releases address a severe buffer overflow vulnerability and other significant issues. Let’s explore the details of these updates a...

Apr 28, 2026 • 3 min read

Open FortiFlaw: Critical Stack-Based Buffer Overflow in Multiple Fortinet Products
FortiFlaw: Critical Stack-Based Buffer Overflow in Multiple Fortinet Products

CVE Research

FortiFlaw: Critical Stack-Based Buffer Overflow in Multiple Fortinet Products

A critical zero-day vulnerability, tracked as CVE-2025-32756 and assigned a CVSS score of 9.8, has been discovered in several Fortinet products, including FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera. This flaw allows remote, unauthenticated attackers to execute arbitrary code or ...

Apr 28, 2026 • 3 min read

Open Critical Flaws in NetScaler ADC & Gateway: CVE-2025-5349 and CVE-2025-5777
Critical Flaws in NetScaler ADC & Gateway: CVE-2025-5349 and CVE-2025-5777

CVE Research

Critical Flaws in NetScaler ADC & Gateway: CVE-2025-5349 and CVE-2025-5777

Two critical vulnerabilities have been identified in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), posing significant risks to enterprise networks. Let’s dive into the details of CVE-2025-5349 and CVE-2025-5777 and the necessary steps for remediation.

Apr 28, 2026 • 4 min read