fuente: https://cybersecuritynews.com/wsus-servers-leveraged-to-deliver-malware/
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments.
The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, capture a database session, and mint malicious “updates” that domain-joined endpoints trust and execute automatically.
Cuatro nuevas vulnerabilidades de Apache NiFi afectan a las instalaciones que ejecutan versiones anteriores a la 2.11.0. Estas fallas permiten a los atacantes e...
Leer artículo →Los atacantes comprometieron la cuenta de GitHub del desarrollador de keyv, una popular biblioteca de almacenamiento clave-valor que registra aproximadamente 12...
Leer artículo →La operación oficial del RAT para Android está rodeada de revendedores más baratos, supuestos proveedores de código fuente, propietarios de servidores independi...
Leer artículo →