SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Open Security Alert: Critical Apache Struts Vulnerability Under Active Exploitation
Security Alert: Critical Apache Struts Vulnerability Under Active Exploitation

CVE Research

Security Alert: Critical Apache Struts Vulnerability Under Active Exploitation

Apache has revealed a critical vulnerability in Apache Struts, a widely utilized Java-based web application framework. The vulnerability tracked as CVE-2024-53677 has a CVSS Score of 9.5 out of 10, indicating critical severity.Struts is a key component in many enterprise environments, valued for its...

Apr 28, 2026 • 2 min read

Open Critical Security Fixes: Sophos Firewall Vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729
Critical Security Fixes: Sophos Firewall Vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729

CVE Research

Critical Security Fixes: Sophos Firewall Vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729

Sophos addressed three critical vulnerabilities in its Firewall product: CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729. These vulnerabilities posed significant security risks, including remote code execution and unauthorized system access.

Apr 28, 2026 • 3 min read

Open Story of Cyberattack: Petya
Story of Cyberattack: Petya

CVE Research

Story of Cyberattack: Petya

The Petya cyberattack, also known as NotPetya, was one of the most devastating cyberattacks in recent history. First discovered in June 2017, it caused widespread damage across the globe, affecting major enterprises and governments. Initially believed to be a ransomware attack, it was later determin...

Apr 28, 2026 • 6 min read

Open Critical Dell SupportAssist Vulnerability (CVE-2024-52535) Exploited
Critical Dell SupportAssist Vulnerability          (CVE-2024-52535) Exploited

CVE Research

Critical Dell SupportAssist Vulnerability (CVE-2024-52535) Exploited

Dell announced a critical security vulnerability affecting its SupportAssist software, widely used for system diagnostics and updates on Dell PCs. Identified as CVE-2024-52535, this flaw poses significant risks to cybersecurity experts and end-users.

Apr 28, 2026 • 3 min read

Open Apple Security Updates in December 2024
Apple Security Updates in December 2024

CVE Research

Apple Security Updates in December 2024

The Apple Security Update December 2024 addresses flaws in Safari, macOS Sonoma, macOS Ventura, and macOS Sequoia. These flaws might allow attackers to execute arbitrary code, access sensitive data, or gain elevated privileges. The updates address issues in components like AppleMobileFileIntegrity, ...

Apr 28, 2026 • 3 min read

Open Estimating the Impact of Vulnerability Debt
Estimating the Impact of Vulnerability Debt

CVE Research

Estimating the Impact of Vulnerability Debt

You can’t easily measure the impact of a vulnerability in your network. To add salt to the wound, the impact is multi-fold. Not just monetarily, risks in your network can damage everything else, too. To measure this impact, security leaders around the world are leveraging the concept of vulnerabilit...

Apr 28, 2026 • 5 min read

Open Microsoft Patches 71 Flaws, 1 Zero Day in December 2024 Patch Tuesday
Microsoft Patches 71 Flaws, 1 Zero Day in December 2024 Patch Tuesday

CVE Research

Microsoft Patches 71 Flaws, 1 Zero Day in December 2024 Patch Tuesday

2024 is finally coming to a close, and what better way to wrap it up than with a Microsoft Patch Tuesday?

Apr 28, 2026 • 4 min read

Open Ivanti Patch Management vs SanerNow and others
Ivanti Patch Management vs SanerNow and others

CVE Research

Ivanti Patch Management vs SanerNow and others

It’s a call no IT or security manager would want to take: “Our systems are down, and we can’t figure out the cause.”  After hours of going through and fro the IT security, the answer starts becoming clear: an unpatched vulnerability was exploited, bringing operations to a halt!Every unpatched system...

Apr 28, 2026 • 6 min read

Open When CVE Met CVE: RomCom Hackers Exploit Firefox and Windows Zero-Days
When CVE Met CVE: RomCom Hackers Exploit Firefox and Windows Zero-Days

CVE Research

When CVE Met CVE: RomCom Hackers Exploit Firefox and Windows Zero-Days

The Russian cybercrime group RomCom has been linked to a series of cyberattacks launched across the world. The notorious hackers are chaining two Firefox and Windows flaws to deliver a backdoor and compromise vulnerable systems.

Apr 28, 2026 • 5 min read