SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Tunnel Trouble: 4.2 Million Hosts, VPNs, and Routers Vulnerable
Tunnel Trouble: 4.2 Million Hosts, VPNs, and Routers Vulnerable

CVE Research

Tunnel Trouble: 4.2 Million Hosts, VPNs, and Routers Vulnerable

“Attackers? Good luck getting past my VPN wall!”. Maybe it’s time to reconsider that. New research just uncovered security vulnerabilities in multiple tunneling protocols that could allow attackers to perform a wide range of attacks in your  “private” network.

Apr 28, 2026 • 5 min read

Open Urgent: Patch Now! Critical Zero-Day CVE-2025-23006 Targets SonicWall SMA Appliances
Urgent: Patch Now! Critical Zero-Day CVE-2025-23006 Targets SonicWall SMA Appliances

CVE Research

Urgent: Patch Now! Critical Zero-Day CVE-2025-23006 Targets SonicWall SMA Appliances

CVE-2025-23006 is a critical zero-day vulnerability affecting SonicWall Secure Mobile Access (SMA) 1000 series appliances. This vulnerability, categorized as a deserialization of untrusted data flaws, resides within the Appliance Management Console (AMC) and Central Management Console (CMC). Exploit...

Apr 28, 2026 • 2 min read

Open The Cybersecurity Landscape of 2024: Key Insights from the Annual Vulnerability Report
The Cybersecurity Landscape of 2024: Key Insights from the Annual Vulnerability Report

CVE Research

The Cybersecurity Landscape of 2024: Key Insights from the Annual Vulnerability Report

The 2024 Annual Vulnerability Report from SecPod reveals a staggering increase in global vulnerabilities, highlighting the ever-evolving nature of cyber threats. With 40,704 vulnerabilities identified in 2024—a 30% increase compared to the previous year—this report serves as a critical resource for ...

Apr 28, 2026 • 4 min read

Open Microsoft Fixes 55 Flaws, 4 Zero Days in February 2025 Patch Tuesday
Microsoft Fixes 55 Flaws, 4 Zero Days in February 2025 Patch Tuesday

CVE Research

Microsoft Fixes 55 Flaws, 4 Zero Days in February 2025 Patch Tuesday

Valentine’s Day is just around the corner, and Microsoft has already brought us the perfect gift – a personalized hamper of 55 fixed vulnerabilities on Patch Tuesday.

Apr 28, 2026 • 3 min read

Open Critical Code Execution Vulnerability (CVE-2025-0411) Detected in 7-Zip
Critical Code Execution Vulnerability (CVE-2025-0411) Detected in 7-Zip

CVE Research

Critical Code Execution Vulnerability (CVE-2025-0411) Detected in 7-Zip

A critical security vulnerability identified as CVE-2025-0411 has been detected in 7-Zip, a widely used file archiver. With a CVSS score of 7.0, this vulnerability allows attackers to bypass the Windows “Mark-of-the-Web” (MotW) security feature. If exploited, it could lead to the execution of malici...

Apr 28, 2026 • 3 min read

Open CVE-2025-23114: Critical Vulnerability in Veeam Backup Products
CVE-2025-23114: Critical Vulnerability in Veeam Backup Products

CVE Research

CVE-2025-23114: Critical Vulnerability in Veeam Backup Products

A critical security vulnerability identified as CVE-2025-23114 affects multiple Veeam backup products. This vulnerability resides within the Veeam Updater component and allows attackers to execute arbitrary code on the affected server through a Man-in-the-Middle (MitM) attack. The issue arises from ...

Apr 28, 2026 • 2 min read

Open Reducing R&D Costs and Speeding Up Time-to-Market – How Integrating SecPod Can Help Businesses
Reducing R&D Costs and Speeding Up Time-to-Market – How Integrating SecPod Can Help Businesses

CVE Research

Reducing R&D Costs and Speeding Up Time-to-Market – How Integrating SecPod Can Help Businesses

When it comes to product development, Technology Vendors are under immense pressure to innovate rapidly, reduce costs, and maintain end-to-end security. This trifecta of challenges often strains resources, delays launches and impacts customer satisfaction. However, integrating SecPod’s advanced tech...

Apr 28, 2026 • 5 min read

Open F5 Issues Warning: BIG-IP Vulnerability Used In Active Exploit Chain
F5 Issues Warning: BIG-IP Vulnerability Used In Active Exploit Chain

CVE Research

F5 Issues Warning: BIG-IP Vulnerability Used In Active Exploit Chain

According to F5, a critical security vulnerability in BIG-IP is being actively exploited after its public disclosure. CVE-2023-46747, resulting in remote code execution, is being further used to exploit CVE-2023-46748, an SQL injection vulnerability.

Apr 28, 2026 • 3 min read

Open Microsoft Patches 159 Flaws, 8 Zero Days in January 2025 Patch Tuesday
Microsoft Patches 159 Flaws, 8 Zero Days in January 2025 Patch Tuesday

CVE Research

Microsoft Patches 159 Flaws, 8 Zero Days in January 2025 Patch Tuesday

2025 is upon us! We’re ringing in the new year with – you guessed it – another Patch Tuesday.

Apr 28, 2026 • 3 min read