ShadowPad APT Weaponizes WSUS RCE CVE-2025-59287
ShadowPad operators are exploiting WSUS vulnerability CVE-2025-59287 to gain SYSTEM-level access on Windows servers. By chaining insecure deserialization, PowerCat reverse shells and DLL side-loading, they turn trusted patching infrastructure into a stealth delivery vector for a mature, modular backdoor.