SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Microsoft December 2022 Patch Tuesday Fixes 48 Vulnerabilities, Including 2 Zero-day!
Microsoft’s December 2022 Patch Tuesday has arrived, bringing fixes for two zero-day vulnerabilities, moreover, one of which is currently being exploited. As a result, 49 flaws are addressed with this patch, seven of which are rated as critical. Therefore, these critical flaws allow for remote code ...

CVE Research
Microsoft November Patch Tuesday 2022 Addresses 65 Vulnerabilities including 6 Zero-Day
Microsoft has released patches for 65 vulnerabilities in its Microsoft November Patch Tuesday of which 6 are actively exploited Zero-Day. Among the 6 Zero-day, CVE-2022-41091 vulnerability is publicly disclosed. Eleven of the 65 vulnerabilities fixed in this security update are classified as ‘Critic...

CVE Research
Microsoft May 2023 Patch Tuesday Fixes 38 Vulnerabilities Including 3 Zero-day!
Microsoft has released its May 2023 Patch Tuesday updates, including fixes for 38 vulnerabilities. This month’s patch is considered one of the smallest in the number of resolved vulnerabilities. However, it is still crucial as it includes a patch for a Windows bug and a Secure Boot bypass flaw, whic...

CVE Research
Microsoft August 2022 Patch Tuesday Addresses 121 Security Flaws Including Two Zero-day Vulnerabilities!
Microsoft fixes 121 vulnerabilities up against 17 ‘critical’ and the rest ‘important’ in its August 2022 Patch Tuesday update. Compared to last month’s Patch Tuesday, critical vulnerabilities are increased by 325%. Therefore, the most critical vulnerabilities are remote code execution and the rest a...

CVE Research
OpenSSL Addressed High-Severity Remote Code Execution Vulnerability- Patch Now!
The OpenSSL has released patches to address OpenSSL high severity vulnerability CVE-2022-2274 and CVE-2022-2097, along with moderate severity ones, in the cryptographic library that could potentially lead to remote code execution in specific scenarios. This done using a vulnerability management tool...

CVE Research
Microsoft October Patch Tuesday Addresses 84 Security Vulnerabilities Including Two Zero-day!
Microsoft has released October 2022 Patch Tuesday security updates, addressing 84 vulnerabilities. Indeed 13 are classified as critical as they allow the most severe types of vulnerabilities like privilege elevation, spoofing, or remote code execution and 71 are classified as important. However, the...

CVE Research
Microsoft November 2021 Patch Tuesday Addresses 55 Vulnerabilities Including 6 zero-days
Microsoft has released Patch Tuesday November 2021 security updates with a total of 55 Vulnerabilities, including six Zero-days rated as critical, while 49 vulnerabilities are rated important. The products covered in November’s security update include Microsoft Exchange, Excel, 3D Viewer, Azure, Mic...

CVE Research
Key Security Flaws That Make Enterprises Vulnerable to LockBit Ransomware
LockBit remains one of the most aggressive ransomware groups, continuously adapting its tactics to target organizations worldwide. Despite law enforcement crackdowns — such as international takedown efforts, infrastructure seizures, and arrests of affiliates — LockBit persists by refining its techni...

CVE Research
Oracle Releases Critical Security Updates January 2023 – Patch Now!
Oracle releases security updates of January 2023, 327 security patches for various product families, including Oracle Communications, Oracle Fusion Middleware, Oracle MySQL, etc. Although, this advisory includes different products which are prone to multiple vulnerabilities.
