hacker-news · Crawled Jul 25, 2026
Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation
1 IoCs 1 Malware
Read original article ↗
AI Summary
A critical remote code execution vulnerability in Microsoft WSUS, tracked as CVE-2025-59287, is under active exploitation with public proof-of-concept code available. The flaw stems from unsafe deserialization of AuthorizationCookie objects via the BinaryFormatter, allowing unauthenticated attackers to execute arbitrary code with SYSTEM privileges. Exploitation has been observed in the wild, with threat actors targeting publicly exposed WSUS instances to deploy PowerShell payloads for reconnaissance and potential supply chain attacks. Organizations are urged to apply emergency patches immediately, as unpatched systems are at high risk of compromise.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | webhook[.]site | Details → |