SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Security Admin’s Savannah
Austin was waiting, and he was worried. It had been 16 hours since he had initiated a vulnerability scan, and it wasn’t complete yet. The talks of a zero-day vulnerability were flying around in the media, and he didn’t even know if it was detected in his network.

CVE Research
Atlassian Critical Vulnerabilities of November 2022 in Atlassian Crowd and Bitbucket Products is addressed. Patch Now!
Atlassian released patches for two critical vulnerabilities of November 2022 affecting Bitbucket Server, Data Center, and Crowd products. Using a vulnerability management tool, these vulnerabilities are tracked as CVE-2022-43781 (Command Injection) and CVE-2022-43782 (Improper Authentication). A Vul...

CVE Research
Two High Severity Vulnerabilities are Addressed in F5 BIG-IP and BIG-IQ Devices. Patch Now!
Two high-severity vulnerabilities are disclosed in F5, affecting the F5 BIG-IP and BIG-IQ devices that can lead to a complete compromise of the system. These vulnerabilities are tracked as CVE-2022-41622 and CVE-2022-41800. Tracking these vulnerabilities is done by a vulnerability management tool.

CVE Research
A Good Defense is the Best Offense: Why is Continuous Vulnerability Management Essential?
Cyberattack surfaces are constantly evolving with an abundance of vulnerabilities. According to SecPod’s security research, the second quarter of 2022 saw a total of 5478 vulnerabilities with 7 zero days.

CVE Research
Vulnerability Management Controls for Critical Security Frameworks
The most common security framework policies, like HIPAA, PCI, NIST, etc., talk about vulnerability management controls, which are a set of recommended safeguards that help mitigate risks and prevent cyber-attacks in your network.

CVE Research
Building a Vulnerability Management Report CISOs Will Love
Are you willing to read reports which are 10,000 pages long? Not me, though. Vulnerability management reports are crucial while strategizing or auditing your organization’s security posture. An effective vulnerability management report should not be long and hard to read but contain all the necessar...

CVE Research
Microsoft November Patch Tuesday 2022 Addresses 65 Vulnerabilities including 6 Zero-Day
Microsoft has released patches for 65 vulnerabilities in its Microsoft November Patch Tuesday of which 6 are actively exploited Zero-Day. Among the 6 Zero-day, CVE-2022-41091 vulnerability is publicly disclosed. Eleven of the 65 vulnerabilities fixed in this security update are classified as ‘Critic...


