Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Security Patch Release

ShadowPad staging through WSUS RCE

Updated 24.11.2025 09:18
Case score 62
Case score 62 Members 3 Latest activity 24.11.2025 09:18 Active exploitation Patch available CVSS: 9.9 Critical
Active exploitation Patch available CVSS: 9.9 Critical
Members 3 First seen 15.10.2025 00:53 Last seen 24.10.2025 19:28 Updated 24.11.2025 09:18

Overview

Attackers are exploiting **CVE-2025-59287** in **Windows Server Update Services (WSUS)** to gain SYSTEM-level execution on exposed Windows Server systems and stage **ShadowPad**. One observed chain used **PowerCat**, `certutil.exe`, and `curl.exe` to reach an external host and install the payload through DLL side-loading. Microsoft said it fixed the flaw in **October 2025**, and available evidence now shows live scanning and exploitation attempts against public WSUS instances. **Eye Security** and **NCSC-NL** reported that the abuse is active, and Microsoft later issued emergency updates and temporary workarounds for systems that could not be patched immediately.