fuente: https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments.
The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, capture a database session, and mint malicious “updates” that domain-joined endpoints trust and execute automatically.
Los responsables del mantenimiento de Handlebars.js han corregido dos fallos críticos que podían permitir la ejecución remota de código. Cada vulnerabilidad de...
Leer artículo →Google ha publicado Chrome 155 en el canal Estable con 247 correcciones de seguridad. Esta actualización corrige cuatro vulnerabilidades críticas de uso de memo...
Leer artículo →Altman advierte sobre más incidentes A medida que la IA generativa adquiere capacidades de agencia para realizar tareas por sí sola, el riesgo de que los modelo...
Leer artículo →