SecPod

Learn Search

Search across all Learn content

SecPod Labs

Security Research

In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

Oracle Releases Critical Security Updates October 2024 – Patch Now!

CVE Research

Oracle Releases Critical Security Updates October 2024 – Patch Now!

Oracle has released its Critical Patch Update (CPU) for October 2024, containing 334 new security patches across various product families, including Oracle Database Server, Oracle MySQL, Oracle Communications, Oracle E-Business Suite, Oracle Fusion Middleware, and more. This update addresses vulnera...

Oct 15, 2024 • 16 min read

Critical Vulnerabilities in Windows, CERT-In Warns Users

CVE Research

Critical Vulnerabilities in Windows, CERT-In Warns Users

Microsoft Windows, the world’s most widely used desktop OS, is at risk! The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity alert, warning Windows users in India of several vulnerabilities in Microsoft products and urging them to update their systems immediately.

Oct 10, 2024 • 2 min read

Adobe Rolls Out Critical Security Updates Across Multiple Products – October 2024

CVE Research

Adobe Rolls Out Critical Security Updates Across Multiple Products – October 2024

In October 2024, Adobe issued security updates to fix several vulnerabilities in Adobe Substance 3D Painter, Adobe Commerce, Adobe Dimension, Adobe Animate, Adobe Lightroom, Adobe InCopy, Adobe InDesign, Adobe Substance 3D Stager, and Adobe FrameMaker. Cyber attackers could exploit these flaws to ga...

Oct 09, 2024 • 4 min read

Microsoft Fixes 118 Flaws, 5 Zero Days in October 2024 Patch Tuesday

CVE Research

Microsoft Fixes 118 Flaws, 5 Zero Days in October 2024 Patch Tuesday

This month, Microsoft released security updates addressing 118 vulnerabilities, of which 5 were publicly disclosed zero days, and 3 were critical RCE flaws. Two of the zero days are known to have been actively exploited. The chart below offers some insight into the types of vulnerabilities found.

Oct 08, 2024 • 4 min read

Zimbra Fixes Actively Exploited CVE-2024-45519 Flaw Allowing Unauthorised Code Execution

CVE Research

Zimbra Fixes Actively Exploited CVE-2024-45519 Flaw Allowing Unauthorised Code Execution

Zimbra has issued an advisory regarding a critical vulnerability identified as CVE-2024-45519, found in its postjournal service. This flaw has been classified  as having a high severity level, allowing unauthenticated users to execute arbitrary commands on vulnerable systems. The vulnerability was f...

Oct 02, 2024 • 4 min read

EP 4: Story Behind a Cyberattack : WannaCry

CVE Research

EP 4: Story Behind a Cyberattack : WannaCry

Welcome back to another episode of “The Story Behind a Cyberattack.” In this episode, we will explore a ransomware attack that occurred in 2017.

Sep 30, 2024 • 5 min read

A Cup Half Empty: Linux RCE Flaws Discovered In CUPS

CVE Research

A Cup Half Empty: Linux RCE Flaws Discovered In CUPS

It’s been a rough year for Linux! The XZ Utils bug caused tremors worldwide in March, and with the recent discovery of a potential chain attack on the CUPS open-source printing system, Linux seems to be caught in a veritable maelstrom of vulnerabilities.

Sep 30, 2024 • 6 min read

Vulnerability Management Framework: A 5-Step Blueprint for Cyber Defense

CVE Research

Vulnerability Management Framework: A 5-Step Blueprint for Cyber Defense

How can you consistently identify and patch security risks while improving your cybersecurity posture. The answer lies in strong vulnerability management framework. 50% of organizations around the world experienced a breach caused by unpatched vulnerabilities. Without a structured approach to manage...

Sep 29, 2024 • 4 min read

What Does CVE Stand For? CVEs Explained!

CVE Research

What Does CVE Stand For? CVEs Explained!

Adam: “Hey did you patch that vulnerability that got detected recently?”

Sep 29, 2024 • 6 min read