SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Mozilla Fixes Two Actively Exploited Zero-Days in Firefox and Thunderbird
Mozilla has released an out-of-band security update for Firefox, Firefox ESR, Firefox Focus, Firefox for Android, and Thunderbird, fixing two critical vulnerabilities (CVE-2022-26485, CVE-2022-26486). Mozilla is aware of the active exploitation of these vulnerabilities. Furthermore, when a patch is ...

CVE Research
5 Things You Didn’t know You Could do in SanerNow
SanerNow can detect and remediate risks and protect your organizations from dangerous cyberattacks using vulnerability management tool. Be it software vulnerabilities or dangerous misconfigurations, SanerNow can easily detect and remediate them. But it can do a lot more than that like auto patching ...
IoT Ransomware Attacks – Next Biggest Challenge For Cyber Warriors – Part 1
CVE Research
IoT Ransomware Attacks – Next Biggest Challenge For Cyber Warriors – Part 1
Ransomware has already managed to carve itself a slot as one of the main cyber security threats in recent years. Individuals, government agencies, and private organizations are each taking precautionary steps to protect against ransomware that can encrypt files beyond one’s reach. IoT ransomware att...
Hillstone Software HS TFTP Server Denial Of Service Vulnerability
CVE Research
Hillstone Software HS TFTP Server Denial Of Service Vulnerability
SecPod Research Team member (Prabhu S Angadi) has found Denial Of Service Vulnerability in Hillstone Software HS TFTP Server. The vulnerability is caused due to improper validation of WRITE/READ Request Parameter containing long file name. The flaw can be exploited to crash the service but can be st...

CVE Research
CVE-2015-2808 : Bar Mitzvah Attack in RC4
Bar Mitzvah Attack, a critical vulnerability discovered in Rivest Cipher 4 software stream cipher. A vulnerability management tool can detect this attack. In cryptography, RC4 is one of the most used software-based stream ciphers in the world. Proper protocols such as Transport Layer Security (TLS) ...

CVE Research
Security Update: Mozilla Fixes Actively Exploited Zero-Days in Firefox
Mozilla fixed two critical zero-days in its popular web browser, Firefox. Using a vulnerability management tool. Mozilla is aware of active exploitation of these vulnerabilities. There is no specific information about the threat groups or malwares utilizing these vulnerabilities. These are the Firef...



