Sophos CTU researchers reported active exploitation of a remote code execution flaw (CVE-2025-59287) in Microsoft WSUS. Attackers used a Base64-encoded PowerShell command to exfiltrate Active Director…
Category: Vulnerabilities / Exploitation / Microsoft
#windows#cve-2025-59287#rce#sophos#vulnerability
The Register reports active exploitation of WSUS CVE-2025-59287, with telemetry noting ~100,000 exploitation hits in seven days and ~500,000 internet-facing servers with WSUS enabled. Google’s GTIG tr…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#wsus#cve-2025-59287#kev#deserialization
Palo Alto Networks Unit 42 details active exploitation of CVE-2025-59287, including process chains indicating cmd.exe and powershell.exe spawned by wsusservice.exe/w3wp.exe, and exfiltration to Webhoo…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#wsus#cve-2025-59287#unit42#hunting
Security researchers have reported active exploitation of CVE-2025-59287 in Microsoft Windows Server Update Services (WSUS). The flaw allows unauthenticated remote code execution through deserializati…
Category: Vulnerabilities / Microsoft / Microsoft
#cve-2025-59287#microsoft#rce#advisory#wsus