Skip to content

Attackers deliver ShadowPad via newly patched WSUS RCE bug

Securityaffairs.Co •Pierluigi Paganini • November 24, 2025

Attackers exploited a patched WSUS flaw (CVE-2025-59287) to gain access, use PowerCat for a shell, and deploy the ShadowPad malware. AhnLab SEcurity intelligence Center (ASEC) researchers reported that threat actors exploited a recently patched WSUS flaw (CVE-2025-59287) to deliver the ShadowPad malware. ShadowPad is a backdoor widely used by China-linked APT groups and privately sold […]

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)

Tools (1)