August 9, 2026
- SpecterOps details turning WSUS into a "backdoor factory." When the WSUS database (SUSDB) runs on a separate SQL Server, an attacker can coerce NTLM auth from the WSUS computer account (e.g., PetitPotam) and relay it to SQL — often landing a session that has EXECUTE on stored procedures like
spImportUpdateandspSaveXMLFragment, enough to craft malicious "bundled" updates (SpecterOps). · Vulnerabilities & Exploits