SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
6 Questions to Ask Yourself Before Outsourcing Vulnerability Management
Consider that you are a FinTech enterprise, and your primary goal has nothing to do with security! Nevertheless, security (Managed vulnerability management) cannot be overlooked. Protecting your company from cyberattacks is highly important. Several industries have been under cyberattack recently, r...

CVE Research
What is Vulnerability Debt?
We have a love-hate relationship with debt. But why am I talking about debt in a vulnerability management blog? Vulnerability debt is a new concept that has gained traction recently, and it is a great way to understand the impact vulnerabilities and security risks have on your network. So, lets dig ...

CVE Research
What Vulnerability Management Metrics Could Make or Break Your Security Program
Do you believe you’re dealing with vulnerabilities correctly? When you run a scan and report a few new vulnerabilities that are unaddressed for longer than 90 days, you’ll try to prioritize them rather than new ones. What if those old vulnerabilities don’t pose more risk than the new vulnerabilities...

CVE Research
CVE-2024-38812: VMWare Patches Critical RCE Flaw In vCenter Server
Broadcom has released security updates addressing CVE-2024-38812, a heap-overflow vulnerability in VMWare vCenter Server. With a CVSS score of 9.8, this critical vulnerability is present in implementing the DCE/RPC protocol and could lead to RCE. An attacker with network access to the vCenter Server...

CVE Research
CVE-2024-9487: GitHub Patches Major Security Flaw in Enterprise Server. Patch Now!
A new critical vulnerability has been found in the GitHub Enterprise Server! CVE-2024-9487, with a staggering CVSS score of 9.5, is a cryptographic signature verification flaw that allows an attacker to gain unauthorized access to vulnerable instances.78io.-[

CVE Research
How North American SMBs Can Leverage Vulnerability Management to Stay Secure
Stopping cyberattacks isn’t easy, but preventing them can be if you properly implement vulnerability management. However, managing vulnerabilities can be daunting, and small and medium-sized businesses (SMBs) around the world and in the North American region in particular are struggling. But why?

CVE Research
The Role of Vulnerability Assessment in Achieving Cyber Resilience for U.S. Enterprises
According to reports, the US ranks the top-most among other countries on the list of being a target for attackers. It faces almost 65% of cyberattacks compared to all the other industries in a year. As one of the world’s largest economies, it hosts numerous multinational corporations and critical in...

CVE Research
F5 fixed a high-severity elevation of privilege vulnerability in BIG-IP
In the constantly changing world of cybersecurity, keeping abreast of vulnerabilities is essential for preserving the integrity of your systems. Recently, F5 has disclosed two significant vulnerabilities: CVE-2024-47139, related to BIG-IQ and CVE-2024-45844 affecting BIG-IP. This blog post will go ...

CVE Research
CSRF and Command Runner Command Injection Vulnerabilities in Cisco DNA Center
The Cisco DNA Center software has been reported with a high-severity security vulnerability (CVE-2021-1257) that allows cross-site request forgery (CSRF) attacks. A vulnerability management software can help in detecting this high-severity vulnerability. Cisco credited the vulnerability report to Be...
