Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Aetherflux reportedly raising Series B at $2 billion valuation

    March 27, 2026

    OpenAI shuts down Sora while Meta gets shut out in court

    March 27, 2026

    VCs are betting billions on AI’s next wave, so why is OpenAI killing Sora?

    March 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Aetherflux reportedly raising Series B at $2 billion valuation
    • OpenAI shuts down Sora while Meta gets shut out in court
    • VCs are betting billions on AI’s next wave, so why is OpenAI killing Sora?
    • 16 of the most interesting startups from YC W’26 Demo Day
    • Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal
    • Silicon Valley’s two biggest dramas have intersected: LiteLLM and Delve
    • Why hiring the weirdos works
    • Conntour raises $7M from General Catalyst, YC to build an AI search engine for security video systems
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Critical Microsoft WSUS flaw exploited in wild after insufficient patch
    Security

    Critical Microsoft WSUS flaw exploited in wild after insufficient patch

    TechurzBy TechurzOctober 25, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft logo
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “Starting around 2025-10-23 23:34 UTC, Huntress observed threat actors targeting WSUS instances publicly exposed on their default ports (8530/TCP and 8531/TCP),” the company wrote in a blog post Friday. “Attackers leveraged exposed WSUS endpoints to send specially crafted requests (multiple POST calls to WSUS web services) that triggered a deserialization RCE against the update service.”

    The exploit activity resulted in the WSUS worker process spawning command prompt and PowerShell instances. A base64-encoded payload was downloaded and executed in PowerShell with the goal of discovering servers on the network and gathering user information which was then sent back to a remote attacker-controlled URL.

    The Huntress report includes detailed indicators of compromise, forensic artifacts, and detection rules in the open Sigma SIEM detection format.

    Critical exploited flaw insufficient Microsoft patch wild WSUS
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleI let Edge’s Copilot Mode buy me a new space heater – here’s how the AI browser did
    Next Article 3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation
    Techurz
    • Website

    Related Posts

    Opinion

    Microsoft hires the team of Sequoia-backed AI collaboration platform, Cove

    March 18, 2026
    Opinion

    The Rippling/Deel corporate spying scandal may have taken another wild turn

    January 23, 2026
    Opinion

    Tiger Global and Microsoft to fully exit Walmart-backed PhonePe via its IPO

    January 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Aetherflux reportedly raising Series B at $2 billion valuation

    March 27, 2026

    OpenAI shuts down Sora while Meta gets shut out in court

    March 27, 2026

    VCs are betting billions on AI’s next wave, so why is OpenAI killing Sora?

    March 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.