Security Affairs reports that threat actors leveraged a recently patched Windows Server Update Services (WSUS) vulnerability (CVE-2025-59287) to deploy the ShadowPad malware, a backdoor commonly associated with China-linked APT groups.
AhnLab Security Intelligence Center discovered that attackers exploited the WSUS flaw to gain access to servers, using PowerCat for a shell and deploying ShadowPad via certutil and curl. The flaw, allowing remote code execution with SYSTEM privileges, poses significant risks to organizations. Microsoft issued an out-of-band fix, but the flaw remains actively exploited, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to list it as a known exploited vulnerability.
Organizations are advised to apply the patch, restrict WSUS access, monitor for suspicious activities and enhance network security.
Source: Security Affairs
