SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Inside CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Attack
Inside CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Attack

CVE Research

Inside CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Attack

A critical authentication bypass vulnerability, CVE-2026-0257, affects Palo Alto Networks PAN-OS GlobalProtect Portal and Gateway deployments. The vulnerability allows a remote, unauthenticated attacker to establish an unauthorized VPN connection by exploiting weaknesses in the handling of authentication override cookies.

Jun 09, 2026

Open HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS

HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS

CVE Research

HTTP/2 Bomb: How an AI Chained Two Decade-Old Techniques Into a Devastating Remote DoS

Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy. The vulnerability has been codenamed HTTP/2 Bomb.

Jun 04, 2026

Open CVE-2026-41940 Attacks, Examples, and Real-World Incidents
CVE-2026-41940_Real world incidents

CVE Research

CVE-2026-41940 Attacks, Examples, and Real-World Incidents

Jun 02, 2026

Open CVE-2026-41940: The Complete Guide to the cPanel & WHM Authentication Bypass, Attack Chain, Detection, and Remediation
Complete guide to CVE-2026-41940

CVE Research

CVE-2026-41940: The Complete Guide to the cPanel & WHM Authentication Bypass, Attack Chain, Detection, and Remediation

Jun 02, 2026

Open CVE-2026-41940 - Critical cPanel Vulnerability Exploited in Mr_Rot13 Backdoor campaign
CVE-2026-41940_Mr_Rot13

CVE Research

CVE-2026-41940 - Critical cPanel Vulnerability Exploited in Mr_Rot13 Backdoor campaign

Jun 01, 2026

Open Breaking Down the FortiClient Breach: CVE-2026-35616 and the Rise of EKZ Infostealer
Breaking Down the FortiClient Breach: CVE-2026-35616 and the Rise of EKZ Infostealer

CVE Research

Breaking Down the FortiClient Breach: CVE-2026-35616 and the Rise of EKZ Infostealer

May 29, 2026

Open Megalodon Supply Chain Attack Compromises 5,500+ GitHub Repositories Through Malicious CI/CD Workflows
Megalodon Supply Chain Attack Compromises 5,500+ GitHub Repositories Through Malicious CI/CD Workflows

CVE Research

Megalodon Supply Chain Attack Compromises 5,500+ GitHub Repositories Through Malicious CI/CD Workflows

May 26, 2026

Open I Asked AI to Break Into My Lab Server. It Changed How I Think About Security.
I Asked AI to Break Into My Lab Server. It Changed How I Think About Security.

CVE Research

I Asked AI to Break Into My Lab Server. It Changed How I Think About Security.

May 26, 2026

Open Showboat Emerges as New Linux Threat in Middle East Cyber Attacks
Showboat Emerges as New Linux Threat in Middle East Cyber Attacks

CVE Research

Showboat Emerges as New Linux Threat in Middle East Cyber Attacks

May 25, 2026