WSUS — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
20
occurrences
First Seen
October 27, 2025
Last Seen
July 16, 2026

WSUS is a technology platform tracked across 12 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed October 27, 2025; most recent activity July 16, 2026.

Overview

WSUS (Windows Server Update Services) is Microsoft's centralized platform for managing and distributing updates within an enterprise. In late 2025, it became a notable attack surface as threat actors leveraged a remote code execution vulnerability to deliver ShadowPad malware, enabling broad system access. Its central role in patch management makes WSUS a high-value target for widespread compromise across networks.

Related Threat Clusters

Recent Intelligence Reports

  • Zero Day Initiative — www.zerodayinitiative.com · July 16, 2026
  • The July 2026 Security Update Review — Thezdi · July 14, 2026
  • CISA Adds CVE-2021 — Webpronews · November 30, 2025
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 73 — Securityaffairs.Co · November 30, 2025
  • Attackers deliver ShadowPad via newly patched WSUS RCE bug — Securityaffairs.Co · November 24, 2025
  • ShadowPad Malware Actively Exploits WSUS Vulnerability for Full System Access — Thehackernews · November 24, 2025
  • Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ShadowPad Malware — Cybersecuritynews · November 21, 2025
  • Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ... — Gbhackers · November 21, 2025

CVSS v3.1 Breakdown