fuente: https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments.
The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, capture a database session, and mint malicious “updates” that domain-joined endpoints trust and execute automatically.
Durante tres semanas, este grupo dejó su servidor completamente expuesto, revelando toda la operación: WP-SHELLSTORM. En su interior se encontraron 27 vulnerabi...
Leer artículo →Según el investigador Chaotic Eclipse, el parche de Microsoft para la vulnerabilidad de día cero RoguePlanet en Windows Defender podría haber introducido nuevos...
Leer artículo →Un nuevo estudio revela que muchas aplicaciones VPN gratuitas para Android no funcionan correctamente. Los investigadores analizaron 281 aplicaciones populares...
Leer artículo →