SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Another Zero-Day in Google Chrome Under Active Exploitation
Google has released a second emergency update for its Chrome Browser this month. Chrome version 89.0.4389.90 for Windows, Mac, and Linux fix five security bugs, one of which is an actively exploited zero-day issue (identified by CVE-2021-21193) which is a Use after free in Chrome’s Blink rendering e...

CVE Research
Microsoft June 2021 Patch Tuesday Addresses 50 CVEs Including Six Zero-Days
Microsoft has released June Patch Tuesday, security updates with a total of 50 vulnerabilities in the family of Windows and Mac operating systems and related products. In the release by Microsoft, 5 were rated as Critical and 45 as Important. The products covered in June’s security update include Mi...

CVE Research
Scan Vulnerabilities In Less Than 5 Minutes! Faster Than Your Coffee Brews.
Who doesn’t love the smell of freshly brewed coffee? There is no better aroma that keeps me up than the smell of freshly brewed coffee. After pondering over my day-to-day tasks, a cup of coffee brings my sanity back and keeps my energy up. This 5-minute brewing time allows me to catch up with my col...
FREAK Attack?
CVE Research
FREAK Attack?
Another potentially dangerous vulnerability called FREAK (Factoring Attack on RSA-EXPORT Keys) is being true to its name and is freaking out all Android and Apple device users. This SSL/TLS vulnerability has over the years exposed millions of Android and Apple devices to attacks when they visit supp...

CVE Research
Cisco IOS XR Zero Day Vulnerabilities Being Actively Exploited in the Wild
The high severity zero-day vulnerabilities found in Cisco IOS XR – An Internetwork Operating System (IOS) that shipped with Cisco’s networking equipment. The vulnerabilities allow an unauthenticated, remote attacker to exhaust process memory. And crash the other processes running on the affected dev...

CVE Research
Are You Sure Uninvited Guests Are Not A Part Of Your Online Meetings?
As the global pandemic, COVID-19 is hitting the world hard, organizations’ workforces are now working from home. No company can easily work without regular meetings, team communications, partner and client calls, webinars, online training, video-conferences etc. Not just corporate organizations, eve...

CVE Research
Cisco Releases Security Updates for Multiple Products
Cisco Security Updates February 2021 has been released address high severity vulnerabilities for twelve different Cisco products using a patch management tool. Exploit on some of these vulnerabilities allow an unauthenticated attacker to execute code with root privileges remotely.


