fuente: https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments.
The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, capture a database session, and mint malicious “updates” that domain-joined endpoints trust and execute automatically.
El FBI y el Servicio Secreto de EE. UU. han emitido un aviso conjunto de ciberseguridad advirtiendo que la campaña FortiBleed, actualmente en curso, está dirigi...
Leer artículo →Ya está disponible una prueba de concepto pública para CVE-2026-59346, una vulnerabilidad crítica de desbordamiento de enteros en el adaptador de red virtual VM...
Leer artículo →En el primer día de Pwn2Own Ireland 2026, investigadores de seguridad lograron explotar 32 vulnerabilidades zero-day únicas, obteniendo recompensas por un total...
Leer artículo →