Threats Tagged 'windows server'
View all threats tagged with 'windows server'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'windows server'
Click on any threat for detailed analysis and mitigation recommendations
0 A critical remote code execution vulnerability (CVE-2025-59287) exists in Microsoft Windows Server Update Services (WSUS) affecting versions from Windows Server 2012 through 2025 with the WSUS role enabled. This flaw allows unauthenticated attackers to execute code with system privileges by targeting exposed WSUS instances on ports 8530 and 8531. Initial patching on October 14, 2025, was incomplete, necessitating an emergency update on October 23. Exploitation has been observed within hours of patch release, with attackers leveraging malicious PowerShell commands for reconnaissance and data exfiltration. Approximately 5,500 WSUS instances are exposed globally, representing a significant attack surface. The vulnerability facilitates initial access and lateral movement within networks. European organizations using WSUS for patch management are at risk of compromise, data theft, and broader network infiltration. Immediate patching and network exposure reduction are critical to mitigate this threat. Join the discussion | AlienVault OTX General | 12/07/2025, 08:53:15 UTC Added: 12/08/2025, 18:23:52 UTC |
The PassiveNeuron campaign is a sophisticated cyberespionage operation targeting Windows Server machines primarily in government, financial, and industrial sectors across Asia, Africa, and Latin America. Attackers gain initial access by exploiting SQL servers and deploy custom implants such as Neursite and NeuralExecutor. These implants employ advanced persistence, evasion, and command execution techniques, using a multi-stage loading process and diverse communication protocols for command and control (C2). Although attribution is uncertain, indicators suggest possible links to Chinese-speaking threat actors. The campaign highlights the critical need for robust server security and continuous monitoring to detect complex multi-stage intrusions. No known exploits are currently in the wild, and the campaign is rated medium severity. The focus on Windows Server environments and SQL exploitation techniques underscores the risk to organizations relying on these technologies. Join the discussion | AlienVault OTX General | 10/21/2025, 14:38:16 UTC Added: 10/21/2025, 16:05:24 UTC |
Showing 1 to 2 of 2 results