SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Apple Security Updates in July 2024
Apple just rolled out its latest security updates for various products in the Apple Security Updates in July 2024. This new update promises to strengthen the security of Apple devices and address several critical vulnerabilities. Here’s a closer look at what these updates entail and why you should i...

CVE Research
Best Practices to take your Vulnerability Assessment Program to the Next Level
Vulnerability assessment is a lengthy process that makes up the foundation of your vulnerability management program. It helps you efficiently detect vulnerabilities and is critical in preventing cyberattacks. But if the foundation is shaky, the entire program can crumble. A Vulnerability Management ...

CVE Research
Google Chrome 126 Update Resolves Critical Security Vulnerabilities!
Google has released Chrome 126, which addresses several high-severity vulnerabilities, including a notable flaw demonstrated at the TyphoonPWN 2024 hacking competition. This update is essential for maintaining the security and integrity of the widely-used web browser.

CVE Research
ARM Mali GPU Drivers are prey to a Wildly exploited Zero-Day flaw!
The leading Processor Technology provider, ARM has announced a zero-day vulnerability in its Open Source Kernel Drivers: Mali GPU Drivers on 7th June 2024. This vulnerability is tracked as CVE-2024-4610 and is said to be exploited in the wild by attackers. Mali GPU Drivers, the widely used ARM GPU D...

CVE Research
GeoServer Critical RCE Flaw Actively Exploited, Warns CISA
GeoServer, an open-source tool used to share and modify geospatial data, is under attack. CVE-2024-36401, which impacts the GeoTools plugin, has a severity rating of 9.8 and arises from the unsafe evaluation of property names as XPath expressions. The GeoTools library API exposes property and attrib...

CVE Research
RCE Flaw Discovered in PHP’s Windows Versions
The well-known open-source scripting language PHP (Hypertext Preprocessor) just had a critical RCE flaw patched and disclosed. Found and reported by security researcher Orange Tsai, CVE-2024-4577 affects the PHP-CGI module in the Windows version and impacts all releases post 5.x.



