Protect Your Microsoft 365 Tenant from New “Direct Send” Phishing Threat
A new phishing technique is actively being used to exploit a Microsoft 365 feature called Direct Send, originally designed to allow internal devices...
Benefit from smart ideas, lower costs, greater productivity. Choose from award-winning printers, software solutions and consumables
We combine professional expertise with a human kind of partnership
Get the right help and advice, register a product and see why our commitment to you matters.
Discover our brand, our global activities and commitments
Huon IT
1 min read
Oct 30, 2025 12:00:00 AM
We’d like to make you aware of a critical security vulnerability (CVSS 9.8) that has recently been identified in Microsoft Windows Server Update Services (WSUS). This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code with SYSTEM privileges on affected servers.
Summary of the Vulnerabilities:
CVE-2025-48983 – CVE-2025-59287 – A remote code execution vulnerability caused by unsafe deserialisation in WSUS’s reporting web services. Attackers can exploit this by sending crafted requests to the WSUS server’s GetCookie() endpoint.
What’s Affected:
Recommended Action:
We strongly encourage reviewing your environment to identify any servers running the WSUS role. If so, apply the out-of-band security update released on October 23, 2025, and reboot the server to complete mitigation.
If patching is not immediately possible, Microsoft recommends:
Disabling the WSUS Server Role, and/or blocking inbound traffic to ports 8530 and 8531 at the host firewall
A new phishing technique is actively being used to exploit a Microsoft 365 feature called Direct Send, originally designed to allow internal devices...
A recently discovered vulnerability affecting Fortinet FortiOS products, which include networking hardware such as firewalls and network equipment....
1 min read
VMware has released an update to patch multiple security vulnerabilities for their products VMware ESXi, vCenter Server, Workstation, and Fusion....