News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
a computer screen with a bunch of code on it

A critical vulnerability in Microsoft Windows Server Update Services, tracked as CVE-2025-59287, is currently being exploited, posing significant risks to multiple organizations. According to the Google Threat Intelligence Group, there have been around 100,000 instances of exploitation in just the past week, with the vulnerability allowing unauthenticated attackers to execute arbitrary code on affected systems. Despite the urgency of the situation, Microsoft has not updated its guidance to reflect this active exploitation, leading to concerns among cybersecurity experts. The vulnerability affects Windows Server versions from 2012 to 2025 and stems from insecure deserialization of untrusted data. Experts warn that the potential consequences of these attacks could be catastrophic for downstream victims, particularly for those that have exposed their WSUS instances to the internet. As such, immediate action is recommended to mitigate risks associated with this vulnerability.

Why do we care?

This one’s bad — and it’s live. A new Windows Server Update Services vulnerability is being hammered.  It lets attackers run code on your servers, no login needed.

And here’s the kicker — Microsoft hasn’t updated its guidance yet, even though Google says it’s being actively exploited. That’s unacceptable when WSUS is the system pushing updates to every machine you manage. If that gets compromised, you could be distributing malware instead of patches.

So don’t wait. Lock down your WSUS, take it off the internet, check your signatures, and verify your patch workflows. This is one of those moments where “wait for guidance” is the wrong move. Act now — or risk becoming the delivery system for your clients’ next breach.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories