Exploitation of Windows Server Update Services Flaw Leads to Data Theft

Exploitation of Windows Server Update Services Flaw Leads to Data Theft

First seen 2 Dec 2025, 18:33 UTC GbhackersCybersecuritynewsHumenglish 81% similarity 22.8

Article Content

Browse articles
ThreatCluster

A critical vulnerability in Windows Server Update Services (WSUS), tracked as CVE-2025-59287, is being actively exploited by attackers to steal sensitive data from organizations globally. The flaw allows for remote code execution without authentication, enabling threat actors to gain control of servers, install malware, and extract valuable information. Sophos researchers have reported real-world exploitation of this vulnerability.

ThreatCluster AI How this analysis works

Community

Browse all →