SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.
SCAP Feed Release : 01-Aug-2018
SCAP Feed Release : 01-Mar-2019
CVE Research
SCAP Feed Release : 01-Mar-2019
The following SCAP content in March 2019 has been released to SCAP Repo and SecPod Saner Solution which contains vulnerabilities like Fedora, Redhat Polkit, NSS vulnerability, etc. SecPod Saner will automatically pull the relevant content on its next scheduled update.
SCAP Feed Release : 01-Jun-2019

CVE Research
Critical Security Vulnerabilities Discovered in JetBrains TeamCity: Urgent Action Required
Recent disclosures have revealed critical vulnerabilities in JetBrains TeamCity. Two vulnerabilities have been identified, namely: CVE-2024-27198 and CVE-2024-27199. It allows unauthenticated attackers to bypass authentication measures and gain unauthorized access to sensitive endpoints within the T...

CVE Research
SolarWinds Fixes Five Potential RCE Vulnerabilities in its Access Rights Manager Solution
Five remote code execution (RCE) vulnerabilities, including three critical severity holes, have been addressed by SolarWinds in its Access Rights Manager (ARM) solution. Three vulnerabilities stand out among the five due to their ability to execute remote code without authentication. These vulnerabi...

CVE Research
“Wanna Cry” and the art of not keeping the systems updated
There is a magic button that is going to save us all. Mathematical modeling, sandboxing, behavioral analysis, machine learning, EDR, what not button. Just click it. Auto Patching vulnerability is gone thing, who is going to sit and roll out those tedious little things. I have invested in magic butto...

CVE Research
SanerNow Risk Prioritization vs CVSS-based Risk Prioritization
A mountain of vulnerabilities and no way of knowing the most critical ones. This is the story of every modern organization’s network, including yours probably. “But what about CVSS-based prioritization?” you might ask. While CVSS in cyber security is a popular method, vulnerability management tools ...

CVE Research
Strategic Server Patch Management to Safeguard Your IT Landscape
Consider this scenario: many vulnerabilities that don’t have a patch are present in the servers and get wildly exploited. These vulnerabilities will act as an open door to hackers, inviting them to have complete control over organizational information. To prevent this situation, an organization sho...

CVE Research
SanerNow’s Agentless Scanner for Endpoint Security
An agentless scanner can detect every vulnerability without leaving a trace. It can silently detect vulnerabilities without installing an agent in each device. The agentless scanner operates discreetly, gathers all the vulnerability information, and self-destructs itself.
