SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Mirai Turns Unsupported D-Link Routers into DDoS Weapons Using CVE-2025-29635
Researchers have uncovered an active Mirai botnet campaign exploiting CVE-2025-29635, a command-injection vulnerability in legacy D-Link DIR-823X routers, to recruit internet-exposed devices into a distributed denial-of-service (DDoS) botnet. Attackers deploy a Mirai malware variant known as “tuxnok...

CVE Research
Prevention in the Age of AI Vulnerability Discovery
Anthropic’s Claude Mythos Preview (Project Glasswing) has pushed a new question into the center of security discussions. Anthropic says Mythos has already identified thousands of zero-day vulnerabilities across critical infrastructure, and that in testing it was able to identify and exploit zero-day...

CVE Research
Deep Dive into FIRESTARTER: Persistent Backdoor on Cisco ASA & Firepower Devices
Modern cyber-espionage campaigns are increasingly shifting away from loud exploitation techniques and toward stealth-focused, persistence-driven operations that abuse trusted infrastructure. Rather than relying on chains of zero-day vulnerabilities or commodity malware, advanced threat actors are no...

CVE Research
Data Breach in the Healing Sphere – Cyberattack Hits 5 Hospitals!
In recent news, a cyberattack hit 5 hospitals and healthcare, forcing some emergency rooms to be closed and ambulances diverted. A ransomware attack on a shared IT service organization caused the attack, which is forcing 5 hospitals in Ontario to reschedule patient appointments. They also forced to ...

CVE Research
Critical Vulnerabilities in SAP Adaptive Server Enterprise (ASE)
The SAP Adaptive Server Enterprise (ASE), previously known as Sybase SQL Server, is a high-performance relational database server that can be hosted on-premise or cloud structure that is used by over 30,000 organizations worldwide, including banking institutions, healthcare companies, security firms...

CVE Research
Microsoft September 2023 Patch Tuesday Fixes 59 Vulnerabilities Including 2 Zero-Day Exploits!
Microsoft has released September 2023 Patch Tuesday security updates, which fixes 59 vulnerabilities. Five are classified as critical, two zero-day(CVE-2023-36802 and CVE-2023-36761), and twenty-four vulnerabilities were related to remote code execution. Vulnerability management tools play a crucial...

CVE Research
5+ Tips to Secure Your Java Code from Attackers
Every software developer must follow certain standards and practices while coding and writing, secure code is one such practice. Everyone who loves to code must ensure their software is not vulnerable to exploits or being a principal cause of a cyber-attack. Here are the few best Java code security ...


