Cybersecurity Dive reports that attacks exploiting the critical untrusted data deserialization bug in Windows Server Update Service, tracked as CVE-2025-59287, have compromised at least 50 organizations.Most of the impacted organizations are in the U.S., including technology firms, manufacturers, healthcare providers, and universities, according to a Sophos report."It's possible this was an initial test or reconnaissance phase, and that attackers are now analyzing the data they've gathered to identify new opportunities for intrusion," said Sophos Director of Threat Intelligence Rafe Pilling.Such findings from Sophos researchers come after the newly emergent threat operation UNC6512 was reported by the Google Threat Intelligence Group to have leveraged the WSUS flaw to facilitate reconnaissance and data exfiltration activities against several entities.Two other threat actors have also conducted intrusions targeted at vulnerable WSUS instances, reported Eye Security researchers, who expounded on an earlier study from Huntress Labs.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




