WSUS is a technology platform tracked across 12 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed October 27, 2025; most recent activity July 16, 2026.
WSUS (Windows Server Update Services) is Microsoft's centralized platform for managing and distributing updates within an enterprise. In late 2025, it became a notable attack surface as threat actors leveraged a remote code execution vulnerability to deliver ShadowPad malware, enabling broad system access. Its central role in patch management makes WSUS a high-value target for widespread compromise across networks.
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
Chinese hackers are exploiting a remote code execution vulnerability in Windows Server Update Services (WSUS) to deploy ShadowPad malware. This attack affects organizations using WSUS for patch management, potentially…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the OpenPLC ScadaBR vulnerability, tracked as CVE-2021-26829, to its Known Exploited Vulnerabilities catalog after confirming active…
A vulnerability in Microsoft WSUS is currently being exploited. This incident has implications for various organizations relying on WSUS for updates, as attackers are actively targeting this weakness. The situation is…
A recent security update for the Windows Server Update Service (WSUS) has caused hotpatching functionality to fail on Windows Server 2025. This issue affects users who rely on hotpatching for seamless updates without…
Attackers exploited a critical vulnerability in Windows Server Update Services (WSUS), identified as CVE-2025-59287, to deploy ShadowPad malware. This backdoor, associated with China-linked APT groups, allows for full…
Microsoft has issued an emergency patch for a critical remote code execution vulnerability in Windows Server Update Services (WSUS), tracked as CVE-2025-59287, which is actively being exploited. Additionally, a zero-day…
Peter Williams, a 39-year-old Australian national and former general manager at L3Harris Trenchant, pleaded guilty to stealing and selling sensitive cyber exploit components to a Russian broker. The stolen materials…