SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
SanerNow has become more powerful than ever. The most awaited 5.0 release is here!
After numerous discussions, brainstorming sessions, day-night development, and rigorous testing, we are thrilled to announce the most exciting release of SecPod in the recent past. SanerNow 5.0 is here to put an end to the eternal search for a full-fledged and automated vulnerability management solu...

CVE Research
CISA Warns To Patch Critical ICMAD Vulnerabilities In SAP Internet Communication Manager(ICM)
On February Patch Tuesday, SAP has released security updates to patch vulnerabilities affecting multiple SAP products, including critical vulnerabilities affecting SAP applications using Internet Communication Manager (ICM). The ICM is one of the most important components of a SAP NetWeaver applicat...

CVE Research
Seven new Meltdown and Spectre-type CPU vulnerabilities that affect Intel, AMD, ARM CPUs
Spectre and Meltdown vulnerabilities are one of the most significant known hardware vulnerabilities that affect the modern computer processors. Meltdown and Spectre vulnerabilities were exploited through malicious programs to retrieve secrets stored in the memory of other running programs, sensitive...

CVE Research
53 Vulnerabilities (2 Critical) Fixed in Microsoft’s January 2024 Patch Tuesday
The second week of the new year has arrived, and with it comes 2024’s first Microsoft Patch Tuesday. This time around, Microsoft has fixed 53 vulnerabilities, including 2 critical ones (CVE-2024-20674 and CVE-2024-20700). Perhaps as a new year’s gift to patch writers, there have been no zero days re...

CVE Research
Terrapin Alert (CVE-2023-48795): Safeguarding Against the Latest SSH Vulnerability
In a recent revelation, a new vulnerability named Terrapin (CVE-2023-48795) has been identified in the Secure Shell (SSH) cryptographic network protocol. This vulnerability poses a serious threat to the integrity of SSH connections, impacting both clients and servers.

CVE Research
Google Fixes Chrome’s Sixth Zero-day Vulnerability in 2023
In response to ongoing attacks exploiting a security vulnerability, Google released a security patch on 28th November, effectively addressing the sixth zero-day flaw in the Chrome browser this year. The company has officially acknowledged the existence of an exploit for the identified security flaw,...



