SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open CVE-2026-41089: MITRE ATT&CK Mapping, SIEM Queries, and Domain Controller Hardening
CVE-2026-41089: MITRE ATT&CK Mapping, SIEM Queries, and Domain Controller Hardening

CVE Research

CVE-2026-41089: MITRE ATT&CK Mapping, SIEM Queries, and Domain Controller Hardening

Jun 11, 2026

Open Qilin Ransomware and CVE-2026-50751: How Threat Actors Weaponized Check Point VPN Infrastructure
Qilin Ransomware and CVE-2026-50751: How Threat Actors Weaponized Check Point VPN Infrastructure

CVE Research

Qilin Ransomware and CVE-2026-50751: How Threat Actors Weaponized Check Point VPN Infrastructure

Jun 11, 2026

Open CVE-2026-41089: Windows Netlogon Patch, IOCs, Detection, and Mitigation Guide
CVE-2026-41089: Windows Netlogon Patch, IOCs, Detection, and Mitigation Guide

CVE Research

CVE-2026-41089: Windows Netlogon Patch, IOCs, Detection, and Mitigation Guide

Jun 11, 2026

Open CVE-2026-41089: Public PoC, Active Exploit Analysis, and Windows Netlogon Risk
CVE-2026-41089: Public PoC, Active Exploit Analysis, and Windows Netlogon Risk

CVE Research

CVE-2026-41089: Public PoC, Active Exploit Analysis, and Windows Netlogon Risk

Jun 11, 2026

Open Tracking Gafgyt C0XMO: How a New Malware Variant Spreads Across Platforms
Tracking Gafgyt C0XMO: How a New Malware Variant Spreads Across Platforms

CVE Research

Tracking Gafgyt C0XMO: How a New Malware Variant Spreads Across Platforms

A newly identified Gafgyt botnet variant, C0XMO, is actively targeting internet-exposed devices through a combination of vulnerability exploitation, weak-credential attacks, and automated lateral movement. Unlike traditional Gafgyt campaigns, C0XMO separates its propagation logic into a dedicated Python-based scanner, enabling it to compromise a wider range of architectures and device types while scaling infections more efficiently.

Jun 11, 2026

Open CVE-2026-41089: Windows Netlogon RCE - One-Packet CLDAP Attack, LSASS Crash, and Active Directory Risk
CVE-2026-41089: Windows Netlogon RCE - One-Packet CLDAP Attack, LSASS Crash, and Active Directory Risk

CVE Research

CVE-2026-41089: Windows Netlogon RCE - One-Packet CLDAP Attack, LSASS Crash, and Active Directory Risk

Jun 10, 2026

Open HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS
HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS

CVE Research

HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. The vulnerability has been codenamed HTTP/2 Bomb.

Jun 10, 2026

Open Two Actors, One Flaw: Gamaredon and UAC-0226 Leverage Delayed WinRAR Patching
Two Actors, One Flaw: Gamaredon and UAC-0226 Leverage Delayed WinRAR Patching

CVE Research

Two Actors, One Flaw: Gamaredon and UAC-0226 Leverage Delayed WinRAR Patching

Two Russia-aligned threat groups, Gamaredon and UAC-0226, are actively exploiting CVE-2025-8088, a high-severity WinRAR path traversal vulnerability, against Ukrainian government, military, and critical infrastructure organizations. Nearly a year after a patch was made available, both groups continued to operate unimpeded.

Jun 10, 2026

Open Three Zero-Days, 206 Flaws Fixed: Microsoft Delivers Record-Breaking June 2026 Patch Tuesday
Three Zero-Days, 206 Flaws Fixed: Microsoft Delivers Record-Breaking June 2026 Patch Tuesday

CVE Research

Three Zero-Days, 206 Flaws Fixed: Microsoft Delivers Record-Breaking June 2026 Patch Tuesday

The second Tuesday of June 2026 marked Microsoft's largest Patch Tuesday release on record, delivering security updates for a massive range of vulnerabilities affecting Windows, Microsoft Office, Azure, Exchange, Hyper-V, Active Directory, Remote Desktop, BitLocker, and numerous core operating system components.

Jun 10, 2026