SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
“GIFSHELL” – Chain Attack in Microsoft Teams
Security researcher Bobby Rauch identified seven different vulnerabilities in Microsoft Teams. These flaws can be used in a series to achieve a new attacking technique named GIFShell attack. However, The GIFShell attack is capable of creating a reverse shell between a user and an attacker. These cra...

CVE Research
Best Practices to Win at Vulnerability Management
Vulnerability management is hard to execute as a continuous process in the long run. In huge networks of organizations, the number of devices, software applications, and the vulnerabilities associated with them is multiplying rapidly. The complexity of devices and software is always growing. Organiz...

CVE Research
Microsoft March 2023 Patch Tuesday Fixes 80 Vulnerabilities Including 2 Critical Zero-Day Exploits!
In March 2023 Patch Tuesday Releases, Microsoft addressed 80 CVEs, of which nine were rated as critical, including 2 Zero-day, 66 as important, and one as moderate. This count also includes two CVEs (CVE-2023-1017 and CVE-2023-1018 ) found in a third-party Trusted Platform Module (TPM2.0) Library. I...

CVE Research
How Many Checks Does Your Vulnerability Management Program Need?
A vulnerability database is a collection of information about security checks and patches. An efficient vulnerability management solution needs a comprehensive vulnerability database with many security checks that can precisely help discover maximum vulnerabilities.

CVE Research
Microsoft February 2023 Patch Tuesday Addresses 77 Vulnerabilities Including 3 Zero-Day!
Microsoft has released February 2023 Patch Tuesday security updates, addressing 77 vulnerabilities. 9 are classified as critical as they allow the most severe type of vulnerability remote code execution, and 68 are classified as important. The products covered in the February security update include...




