hacker-news · Crawled Jul 25, 2026

Newly Patched Critical Microsoft WSUS Flaw Comes Under Active Exploitation

1 IoCs 1 Malware
Read original article ↗

AI Summary

A critical remote code execution vulnerability in Microsoft WSUS, tracked as CVE-2025-59287, is under active exploitation with public proof-of-concept code available. The flaw stems from unsafe deserialization of AuthorizationCookie objects via the BinaryFormatter, allowing unauthenticated attackers to execute arbitrary code with SYSTEM privileges. Exploitation has been observed in the wild, with threat actors targeting publicly exposed WSUS instances to deploy PowerShell payloads for reconnaissance and potential supply chain attacks. Organizations are urged to apply emergency patches immediately, as unpatched systems are at high risk of compromise.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain webhook[.]site Details →

MITRE ATT&CK TTPs 6 techniques