SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open The Hidden Risks of Third-Party Resources and How to Avoid Them
The Hidden Risks of Third-Party Resources and How to Avoid Them

CVE Research

The Hidden Risks of Third-Party Resources and How to Avoid Them

Businesses today increasingly depend on a wide variety of third-party resources to meet their cloud computing requirements, which range from customer service and analytics to data security and storage. Although this interconnected ecosystem drives operational efficiency and workforce productivity, i...

Apr 28, 2026 • 10 min read

Open Understanding DDoS Attacks: A Comprehensive Guide
Understanding DDoS Attacks: A Comprehensive Guide

CVE Research

Understanding DDoS Attacks: A Comprehensive Guide

Businesses and services rely heavily on online presence, the threat of cyberattacks looms large. Among these threats, Distributed Denial of Service (DDoS) attacks stand out due to their ability to paralyze websites and online services. A DDoS attack occurs when multiple compromised systems target a ...

Apr 28, 2026 • 7 min read

Open How New Year Traffic Stresses Your Cloud Security (And What to Do About It)
How New Year Traffic Stresses Your Cloud Security (And What to Do About It)

CVE Research

How New Year Traffic Stresses Your Cloud Security (And What to Do About It)

The New Year is here — a time for fresh beginnings, renewed goals, and ambitious business plans. However, it’s also a period where cybercriminals remain active, exploiting vulnerabilities that arise during high-traffic events and transitions into the new calendar year.

Apr 28, 2026 • 5 min read

Open Critical Path Traversal Vulnerabilities (CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, and CVE-2024-13159) in Ivanti Endpoint Manager
Critical Path Traversal Vulnerabilities (CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, and CVE-2024-13159) in Ivanti Endpoint Manager

CVE Research

Critical Path Traversal Vulnerabilities (CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, and CVE-2024-13159) in Ivanti Endpoint Manager

Ivanti, an IT management solutions, has identified and addressed four critical vulnerabilities in its Endpoint Manager (EPM) software. These vulnerabilities, identified as CVE-2024-10811, CVE-2024-13161, CVE-2024-13160, and CVE-2024-13159, have been assigned a CVSS score of 9.8, indicating their hig...

Apr 28, 2026 • 2 min read

Open Critical Vulnerability Uncovered: CVE-2025-0282 Puts Ivanti Systems at Risk
Critical Vulnerability Uncovered: CVE-2025-0282 Puts Ivanti Systems at Risk

CVE Research

Critical Vulnerability Uncovered: CVE-2025-0282 Puts Ivanti Systems at Risk

Ivanti has disclosed a critical vulnerability identified as CVE-2025-0282, affecting several of its products, including Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. With a CVSS Score of 9.0, this stack-based buffer overflow vulnerability allows remote, unauthenticated attacker...

Apr 28, 2026 • 3 min read

Open CVE-2023-34990: Critical Path Traversal Flaw Found in Fortinet FortiWLM
CVE-2023-34990: Critical Path Traversal Flaw Found in Fortinet FortiWLM

CVE Research

CVE-2023-34990: Critical Path Traversal Flaw Found in Fortinet FortiWLM

On 12 May 2023, Horizon3 researcher Zach Hanley found an unauthenticated limited file read vulnerability in FortiWLM that he promptly disclosed to Fortinet. On 18 December 2024, it was given a name—CVE-2023-34990—and Fortinet released an advisory warning users of its severity.

Apr 28, 2026 • 2 min read

Open CVE-2014-2120: Ten-year-old Cisco ASA Flaw Exploited In The Wild
CVE-2014-2120: Ten-year-old Cisco ASA Flaw Exploited In The Wild

CVE Research

CVE-2014-2120: Ten-year-old Cisco ASA Flaw Exploited In The Wild

First discovered in 2014 by researcher Jonathan Claudius, CVE-2014-2120 is a vulnerability caused by insufficient input validation in the WebVPN login page of Cisco Adaptive Security Appliance (ASA) Software. This flaw could allow an unauthenticated remote attacker to execute an XSS attack against a...

Apr 28, 2026 • 2 min read

Open CVE-2024-50379: Apache Tomcat Remote Code Execution Vulnerability
CVE-2024-50379: Apache Tomcat Remote Code Execution Vulnerability

CVE Research

CVE-2024-50379: Apache Tomcat Remote Code Execution Vulnerability

Apache Tomcat, one of the most widely used open-source application servers for running Java applications, has long been trusted by organizations around the world. However, as with all widely used software, vulnerabilities can pose significant risks if not addressed promptly.

Apr 28, 2026 • 3 min read

Open Security Alert: Critical Remote Code Execution Vulnerability Discovered in Sophos Firewall
Security Alert: Critical Remote Code Execution Vulnerability Discovered in Sophos Firewall

CVE Research

Security Alert: Critical Remote Code Execution Vulnerability Discovered in Sophos Firewall

Sophos has addressed three security flaws in Sophos Firewall products that could enable remote, unauthenticated attackers to execute SQL injection and remote code execution, as well as gain privileged SSH access to affected devices.

Apr 28, 2026 • 3 min read