THREATOPS
THREAT OPSThreat News › Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1

Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1

medspecteropsPublished 2026-08-05

<p class="wp-block-paragraph"><em><strong>TL;DR:</strong> This is part 1 of a 2 part blog series sharing what I have discovered in my Windows Service Update Service (WSUS) research. If the WSUS database is configured on a separate server from the upstream WSUS server, we can coerce the WSUS computer account to the WSUS database and establish a SQL session. With this access, we can create custom ma

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-1/