fuente: https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments.
The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, capture a database session, and mint malicious “updates” that domain-joined endpoints trust and execute automatically.
El destacado repositorio de modelos y conjuntos de datos de código abierto Hugging Face reveló un sofisticado ciberataque contra su ecosistema principal. Un eni...
Leer artículo →Según watchTowr, una tercera vulnerabilidad de SharePoint Server, corregida por Microsoft como parte de su actualización de seguridad de julio de 2026, está sie...
Leer artículo →Una vulnerabilidad recientemente descubierta en el servidor oficial Azure DevOps MCP de Microsoft revela cómo un comentario invisible en una solicitud de extrac...
Leer artículo →