SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Inside CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Attack
A critical authentication bypass vulnerability, CVE-2026-0257, affects Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway deployments. The vulnerability allows a remote, unauthenticated attacker to establish an unauthorized VPN connection by exploiting weaknesses in the handling of authentication override cookies.
HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS
CVE Research
HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS
Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy. The vulnerability has been codenamed HTTP/2 Bomb.







