Vulnerability Management

Dozens impacted by active WSUS vulnerability abuse

Cybersecurity Dive reports that attacks exploiting the critical untrusted data deserialization bug in Windows Server Update Service, tracked as CVE-2025-59287, have compromised at least 50 organizations.

Most of the impacted organizations are in the U.S., including technology firms, manufacturers, healthcare providers, and universities, according to a Sophos report.

"It's possible this was an initial test or reconnaissance phase, and that attackers are now analyzing the data they've gathered to identify new opportunities for intrusion," said Sophos Director of Threat Intelligence Rafe Pilling.

Such findings from Sophos researchers come after the newly emergent threat operation UNC6512 was reported by the Google Threat Intelligence Group to have leveraged the WSUS flaw to facilitate reconnaissance and data exfiltration activities against several entities.

Two other threat actors have also conducted intrusions targeted at vulnerable WSUS instances, reported Eye Security researchers, who expounded on an earlier study from Huntress Labs.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds