SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Zimbra Collaboration Suite High Severity Zero-Day RCE Vulnerability is Exploited in Wild!
Zimbra Collaboration Suite (ZCS), a widely used web client and email server, has an unpatched zero-day remote code execution (RCE) vulnerability that hackers are known to be actively exploiting. The vulnerability is assigned with CVE-2022-41352 and is rated critical (CVSS v3 score: 9.8). This vulner...

CVE Research
How do you Implement Vulnerability Management for PCI Compliance?
Payment Card Industry Data Security Standard (PCI DSS) is a data safety requirement to be followed by all companies and organizations that store, process, or transmit credit card/financial information. If your organization handles financial data, it’s highly likely you’ve heard of it before and are ...

CVE Research
Exploit Kits: Cybercriminal’s ultimate weapon
Exploit kits are automated malicious software programs which target client-side application vulnerabilities like Web Browsers, Add-ons, Adobe Flash Player, Adobe Reader, Java Runtime Environment, etc. Therefore, Vulnerability Management Software can help you prevent these.

CVE Research
Microsoft June 2023 Patch Tuesday Fixes 78 Vulnerabilities Including 6 Critical Vulnerabilities
Microsoft’s June 2023 Patch Tuesday addressed 78 flaws, including 38 remote code execution (RCE) vulnerabilities. Among the critical vulnerabilities, a severe RCE bug (CVE-2023-29357) in Microsoft SharePoint Server stood out, potentially allowing unauthenticated attackers on the same network to acce...

CVE Research
Microsoft April’s 2022 Patch Tuesday Addresses 119 Vulnerabilities Including 2 Zero-Days
Microsoft has released April’s 2022 Patch Tuesday security updates for 119 detected vulnerabilities, including two zero-days and nine being rated as critical. Moreover, the products covered in April’s 2022 patch Tuesday security update include Windows User Profile Service, Windows Common Log File Sy...

CVE Research
What are the Most Critical Vulnerabilities of 2021?
2021 was yet another year of IT security chaos and uncertainties. The year saw a drastic acceptance of the hybrid work model among various organizations across the globe. Whatever your working model is, on-premises, remote, or hybrid, one crucial process will remain the same in your security strateg...

CVE Research
A Good Defense is the Best Offense: Why is Continuous Vulnerability Management Essential?
Cyberattack surfaces are constantly evolving with an abundance of vulnerabilities. According to SecPod’s security research, the second quarter of 2022 saw a total of 5478 vulnerabilities with 7 zero days.


