SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Three Takeaways from the National Security Agency’s Cybersecurity Advisory in October 2020
On October 20, 2020, the National Security Agency (NSA), a national-level intelligence agency of the United States Department of Defense, released an NSA cybersecurity advisory highlighting 25 vulnerabilities in commonly-used software that are currently under active exploitation. They released the a...

CVE Research
Privilege Escalation Vulnerability in MySQL / MariaDB / PerconaDB databases ( CVE-2016-5616 / CVE-2016-6663 )
Privilege escalation is the method of exploiting a bug, design flaw, or configuration issue in an operating system or software application to gain access to resources that are having restrictions to use by other users. An independent researcher Dawid Golunski exposed a privilege escalation vulnerabi...
BlueBorne Attack: Millions of Devices at Risk
CVE Research
BlueBorne Attack: Millions of Devices at Risk
Over 5.3 billion devices across Windows, Linux, ios, and Android are affected by a new attack vector called BlueBorne Attack. Unless traditional attacks, this attack vector spreads over the air via Bluetooth, and the hacker does not need to pair with each device. A good Vulnerability Management Tool...

CVE Research
Updated: Microsoft September Patch Tuesday Addresses 63 Security Vulnerabilities, Including Two Zero-day!
Microsoft released its monthly (September’s) security update, Patch Tuesday, disclosing 63 vulnerabilities across the company’s hardware and software line. Microsoft September 2022 Patch Tuesday security update is observed to have a sharp decline from last month’s number of issues disclosed by Micro...

CVE Research
EternalRocks – The New and More Sophisticated ‘Doomsday’ Worm
The Blackhats have created a new strain of malware that targets the same vulnerability as the WannaCry ransomware from the first week of May. However, these targeted vulnerabilities can be patched using auto patching.




