Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Guide to Enterprise Patch Management

CVE Research

Guide to Enterprise Patch Management

Patch Management stands as a critical component of a robust cybersecurity strategy. It involves the timely updating of software to fix vulnerabilities, enhance functionality, and ensure overall security.

Jul 24, 2024 • 4 min read

Critical Flaw in Cisco Smart Software Manager Allows Attackers to Control the Device

CVE Research

Critical Flaw in Cisco Smart Software Manager Allows Attackers to Control the Device

A critical vulnerability in the Cisco Smart Software Manager On-Prem (SSM On-prem) authentication system that allowed unauthenticated, remote attackers to change the password of any user, including that of administrators, has been fixed.

Jul 21, 2024 • 2 min read

NIST Vulnerability Management

CVE Research

NIST Vulnerability Management

Cybersecurity is important. It’s a hard truth we all must accept. Cyber threats are constantly evolving, targeting individuals, businesses, and governments. As much as I hate to say it, protecting sensitive information and maintaining secure systems is crucial.

Jul 18, 2024 • 4 min read

GeoServer Critical RCE Flaw Actively Exploited, Warns CISA

CVE Research

GeoServer Critical RCE Flaw Actively Exploited, Warns CISA

GeoServer, an open-source tool used to share and modify geospatial data, is under attack. CVE-2024-36401, which impacts the GeoTools plugin, has a severity rating of 9.8 and arises from the unsafe evaluation of property names as XPath expressions. The GeoTools library API exposes property and attrib...

Jul 17, 2024 • 4 min read

The Story of Mis-Tech: Ep 2: The Search for a Vulnerability Management Tool That Works!

CVE Research

The Story of Mis-Tech: Ep 2: The Search for a Vulnerability Management Tool That Works!

A quick recap

Jul 14, 2024 • 5 min read

Exim Mail Server Vulnerability: A Critical Threat Affecting Millions

CVE Research

Exim Mail Server Vulnerability: A Critical Threat Affecting Millions

A critical vulnerability (CVE-2024-39929) in the Exim mail transfer agent could enable attackers to deliver malicious attachments to users’ inboxes. The flaw, rated 9.1 out of 10 on the CVSS scale, affects versions up to 4.97.1 and has been fixed in version 4.98.

Jul 14, 2024 • 2 min read

Microsoft’s July 2024 Patch Tuesday Fixes Four Zero Days; Releases Patches for 142 Vulnerabilities

CVE Research

Microsoft’s July 2024 Patch Tuesday Fixes Four Zero Days; Releases Patches for 142 Vulnerabilities

Microsoft released its July edition of Patch Tuesday. In it, Microsoft addressed 142 flaws and patched four zero-day bugs.

Jul 09, 2024 • 5 min read

Ghostscript Vulnerability Actively Exploited in the Wild

CVE Research

Ghostscript Vulnerability Actively Exploited in the Wild

A severe remote code execution (RCE) vulnerability in the widely used Ghostscript library is being actively exploited. This vulnerability, identified as CVE-2024-29510, affects Ghostscript versions 10.03.0 and earlier. Ghostscript, a document conversion tool, is commonly found on Linux systems and i...

Jul 08, 2024 • 2 min read

Unveiling regreSSHion: Critical OpenSSH Flaw Found In Linux Systems

CVE Research

Unveiling regreSSHion: Critical OpenSSH Flaw Found In Linux Systems

Linux users beware! OpenSSH flaw, a networking utility installed on every Unix and Linux system by default, is affected by a critical signal handler race condition vulnerability.

Jul 03, 2024 • 3 min read