Raphael Walter 리트윗함

#WSUS #Vulnerability #DFIR #Hunting
Here are some tips to help identify a WSUS server that may have been compromised through the recent CVE-2025-59287 vulnerability.


The Shadowserver Foundation@Shadowserver
Attention - Microsoft WSUS CVE-2025-59287 incidents! We are observing exploitation attempts based on a published POC. We have also began fingerprinting exposed WSUS instances (ports 8530/8531) with at least 2800 seen on 2025-10-25 (not necessarily vulnerable).
English























