Patch/Configuration Management, Vulnerability Management

Attacks involving critical WSUS vulnerability under investigation

Plain code with the word "cyberattack" in red.

Malicious actors have escalated intrusions exploiting the critical untrusted data flaw in Windows Server Update Service, tracked as CVE-2025-59287, following the release of a proof-of-concept flaw last week, Cybersecurity Dive reports.

Intrusions involving the flaw have already been launched by the newly emergent UNC6512 threat operation to compromise various organizations, according to the Google Threat Intelligence Group. Initial access and subsequent reconnaissance efforts to associated environments have allowed UNC6521 to conduct data exfiltration from the targeted entities, said researchers.

Such a development comes after the bug which has already been added to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog was reported by Eye Security researchers to have been exploited by two or more adversarial forces since Friday.

Another report from Palo Alto Networks Unit 42 researchers noted attacks exploiting the vulnerability to execute illicit PowerShell commands. Nearly 2,800 internet-exposed Windows Server instances were observed by The Shadowserver Foundation to be at risk of potential intrusions.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds