SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
Google discloses zero-day Vulnerability in Windows kernel
CVE Research
Google discloses zero-day Vulnerability in Windows kernel
Google discloses a Windows zero-day vulnerability in the Windows kernel. That is currently in exploitation in the wild by Black Hats. This was disclosing after Microsoft failed to release a patch within the 7-day deadline. Also, a reliable vulnerability management tool can prevent these issues.

CVE Research
ESXiArgs Ransomware Actively Targeting Vulnerable Unpatched VMware ESXi Servers. Patch Now!
A new ESXiArgs ransomware is actively targeting VMware ESXi servers that are unpatched against a two-year-old remote code execution vulnerability known as CVE-2021-21974. The vulnerability originates from a heap overflow problem within the OpenSLP service, leaving it open to exploitation by attacker...

CVE Research
5 Stages of Vulnerability Management Maturity Model: Know How Mature is your Model!
In today’s rapidly evolving threat landscape, organizations face a constant barrage of vulnerabilities that can potentially expose their systems to cyber threats. To effectively address this challenge, a vulnerability management maturity model becomes essential. And a good vulnerability management t...

CVE Research
Microsoft January 2023 Patch Tuesday Addresses 98 Vulnerabilities Including a Zero-Day!
Microsoft has released January 2023 Patch Tuesday security updates, addressing 98 vulnerabilities. Also, 11 are classified as critical as they allow the most severe types of vulnerabilities like privilege elevation, security feature bypass, or remote code execution, and 87 are classified as importan...

CVE Research
Retbleed: Intel and AMD Processors Information Disclosure Vulnerability. Patch Now!
Researchers have discovered a new Speculative execution attack called Retbleed, which affects both Intel and AMD processors that can result in information disclosure vulnerability. CVE-2022-29900 (AMD) is the tracking identifier for AMD, while CVE-2022-29901 (Intel) is the tracking identifier for In...

CVE Research
Microsoft July 2022 Patch Tuesday Addresses 84 Security Vulnerabilities Including a Zero-day!
Microsoft fixes 84 vulnerabilities, including four critical, one zero-day, and 79 others as important in its July 2022 Patch Tuesday update. All four critical vulnerabilities are of remote code execution, and there are about 12. The rest include elevation of privileges (zero-day flaw), Information D...

CVE Research
OpenSSH Crypt CPU Consumption
OpenSSH is a free suite of connectivity tools, aka OpenBSD Secure Shell, which provides secure encryption for remote login and file transfer between two hosts over a network. A Vulnerability Management tool can resolve the attacks on OpenSSH Vulnerabilities (CVE-2016-6515).


