Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints

A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed across enterprise environments. The research, published by SpecterOps researcher Beyviel David, demonstrates how organizations hosting WSUS on an external SQL Server database face a critical operational risk: attackers with local network access can coerce authentication, […]

This article has been indexed from Cyber Security News

Read the original article: