ao link
Affino
Search Teiss
My Account
Remember Login
My Account
Remember Login

CISA and NSA issue urgent guidance to secure WSUS and Microsoft exchange servers

The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), in coordination with international partners, have issued critical guidance to organisations running on-premises or hybrid instances of Microsoft Exchange Server and Windows Server Update Services (WSUS) following active exploitation of a severe flaw. 

Linked InXFacebook

The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA), in coordination with international partners, have issued critical guidance to organisations running on-premises or hybrid instances of Microsoft Exchange Server and Windows Server Update Services (WSUS) following active exploitation of a severe flaw. 


The guidance emphasises enforcing zero-trust principles, restricting administrative access, enforcing multifactor authentication, hardening transport and authentication protocols (TLS, HSTS, Kerberos, SMB), decommissioning outdated Exchange servers, and maintaining rigorous patching and security baselines.

 
Specifically, CISA updated its alert to include CVE‑2025‑59287, a newly patched remote code execution vulnerability in WSUS, and flagged several incident cases where attackers used SYSTEM-level processes and Base64-encoded PowerShell commands to compromise systems.


For organisations, this serves as a clear reminder that foundational infrastructure components (update services, messaging servers) remain prime targets and that rigorous hardening and monitoring are non-negotiable. 

Linked InXFacebook
Affino

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543