Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

WSUS exploitation and ClickFix scams: what CISO teams should act on


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: Active WSUS exploitation, LockBit 5.0’s return, ClickFix fullscreen-update scams, and 73 zero-days from Pwn2Own Ireland show how quickly exposure moves from proof of concept to operational abuse, according to FireCompass’s weekly report. The pattern is a speed problem as much as a patching problem: controls must detect browser-to-PowerShell abuse, segment exposed services, and reduce execution pathways before attackers weaponise them.

NHIMG editorial — based on content published by FireCompass: Weekly Report on New Hacking Techniques and Critical CVEs, 22 Oct to 28 Oct 2025

By the numbers:

  • Researchers demonstrated 73 zero-days at Pwn2Own Ireland across iPhone 16, Galaxy S25, QNAP and Synology NAS, smart home devices, and WhatsApp.
  • CVE-2025-59287 carries a CVSS score of 9.8 and enables unauthenticated remote code execution in WSUS.

Questions worth separating out

Q: What should security teams do first when a fake update scam can launch PowerShell on user endpoints?

A: First, remove the easiest execution paths.

Q: Why do exposed management services create such a fast exploitation window?

A: Exposed management services are attractive because they often trust incoming input and run with high privilege.

Q: What breaks when ransomware targets ESXi, Linux, and Windows at the same time?

A: Recovery becomes harder because the attack is no longer confined to one operating system.

Practitioner guidance

  • Restrict PowerShell execution paths Block or tightly constrain PowerShell on user endpoints, especially where browser content can trigger code execution.
  • Isolate exposed management services Remove WSUS and similar management interfaces from internet exposure, place them in segmented admin networks, and verify that only required hosts can reach them.
  • Validate ransomware recovery paths Test restore procedures for ESXi, Linux, Windows, and backup systems together so that recovery does not depend on the same privilege paths an attacker would abuse.

What's in the full article

FireCompass's full report covers the operational detail this post intentionally leaves for the source:

  • More granular breakdowns of the ClickFix tradecraft, including the exact user interaction flow and payload delivery steps
  • The specific WSUS exploitation indicators and hunting approach described alongside the CVE-2025-59287 analysis
  • Additional detail on LockBit 5.0 tactics across ESXi, Linux, and Windows environments
  • The report’s wider weekly threat context, including underground coordination and emerging phishing patterns

👉 Read FireCompass's weekly threat report on new hacking techniques and critical CVEs →

WSUS exploitation and ClickFix scams: what CISO teams should act on?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Attack surface compression is now a governance problem, not just a patching problem. When exploitation, social engineering, and post-exploitation tooling arrive in the same weekly window, the control question changes from "what is vulnerable?" to "what can be reached, executed, and persisted on today?" That is why NIST CSF and CIS Controls need to be operationalised around exposure, identity, and execution pathways together. Practitioners should treat public exploitability as a multi-control event, not a ticket in isolation.

A few things that frame the scale:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging (37%) and over-privileged accounts (37%), according to The State of Non-Human Identity Security.
  • A separate finding shows that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, which helps explain why exposure management remains fragile.

A question worth separating out:

Q: How should teams prioritise vulnerabilities when zero-days and social engineering appear together?

A: Prioritise by reachability, exploitability, and blast radius. A reachable management service or a scam that can execute code on a privileged endpoint deserves faster action than an isolated issue with limited exposure. Combine exposure management with identity controls so the same patching queue also reflects who can execute, administer, or persist.

👉 Read our full editorial: Weekly threat report on WSUS exploitation, LockBit and ClickFix



   
ReplyQuote
Share: