Capacitify Capacitify
    Advanced Search
  • Login
  • Register

  • Night mode
  • © 2025 Capacitify
    About • Directory • Contact Us • Developers • Privacy Policy • Terms of Use

    Select Language

  • English

Events

Browse Events My events

Blog

Browse articles

Market

Latest Products

More

Forum Popular Posts Offers
Upgrade Now Events Market Blog See all

Discover posts

Posts

Members

Ventures

Program

Blog

Market

Events

Forum

Jobs

Xphiz Digital Technologies Limited
Xphiz Digital Technologies Limited
7 w

Critical Windows Update Glitch: USB & Performance Issues Detected

At Xphiz Digital Technologies, we stay ahead of critical system updates to ensure uninterrupted operations for our clients.
Microsoft’s latest cumulative update - KB5066835 (OS Build 26100.6899) - released on October 14, 2025, is causing major disruptions across Windows 11 (24H2/25H2) and Windows Server 2025 environments.

🔹 Primary Issue:
USB keyboards and mice become completely unresponsive in the Windows Recovery Environment (WinRE) - preventing access to vital recovery and repair tools.
🔹Other Reported Problems:
• Failed localhost network connections
• Update installation errors
• Blank File Explorer preview panes
• Sluggish system performance and app delays
Microsoft has acknowledged the issue (October 17) and is developing a fix.

✅ Recommended Actions:
• Avoid using WinRE until the patch is fixed
• Use Windows installation media for recovery tasks
• Uninstall KB5066835 only if absolutely necessary (note: this reopens security risks)
• Pause automatic updates in critical systems

At Xphiz Digital Technologies, our IT team continues to test updates in controlled environments before full deployment - safeguarding system integrity and minimizing operational risks.

Key Insight: Even essential security patches can trigger unexpected issues. Proactive monitoring, staged deployment, and reliable backup processes remain the best defense against downtime.
#xphizdigitaltechnologies #windows11 #microsoftupdate #itsupport #systemadmin #cybersecurity #techupdate #xphiz

image
Like
Comment
Share
Ayokunle Olaniregun
Ayokunle Olaniregun  
7 w

What happened in EASY terms:
• WSUS (Windows Server Update Services) is Microsoft’s tool that companies use to centrally download and push Windows updates to their computers.
• A critical bug (CVE-2025-59287, CVSS 9.8) was fixed by Microsoft in October 2025. Security researchers / attackers have published a proof-of-concept (PoC) exploit that shows how the bug can be used in the real world.

WHY SO BAD - (simple analogy)
Think of WSUS as a trusted mailroom. WSUS receives a small encrypted note (an “AuthorizationCookie”). Because of a bug, WSUS decrypts that note and then trusts the contents so blindly that it treats those contents like executable instructions. An attacker can craft a malicious note so that when WSUS “reads” it, the server ends up running attacker code with SYSTEM privileges - the highest level on Windows. Because the service is network-facing inside many networks, an attacker doesn’t even need to be logged in (it’s unauthenticated).

Technically: WSUS uses .NET’s Binary Formatter to deserialize decrypted cookie data. Binary Formatter can instantiate objects during deserialization and, with the fed attackers data, it can be tricked into running code. That unsafe deserialization is the root cause.

REAL RISKS
• An attacker who successfully exploits this gets SYSTEM, so they can install ransomware, move laterally, steal updates, or modify update content - very high impact for enterprises.
• WSUS servers could be used to infect many machines if attackers tamper with update infrastructure (i.e., it could be wormable(virus) inside a network).

IMMEDIATE ACTIONS (what to do now)
1. Patch WSUS immediately - apply Microsoft’s security update for CVE-2025-59287 on every WSUS server. This is the primary fix. (If you manage many servers, prioritize internet-facing and central WSUS servers.)
2. If you can’t patch immediately:
a. Block network access to your WSUS server from untrusted networks. Restrict access to management hosts only (firewall rules / NSGs). WSUS typically listens on web ports (HTTP/HTTPS) - limit those.
b. Consider isolating the WSUS server from the general LAN until patched.
3. Harden and monitor:
• Review IIS / HTTP access logs to look for suspicious requests targeting WSUS endpoints (the PoC abuses cookie endpoints).
• Watch for unexpected child processes, new services, unusual network connections from the WSUS host, or modified update files.
4. Search for compromise indicators: look for signs of code execution with SYSTEM around the time of suspicious requests, new admin accounts, or changes to update catalogs. If you suspect compromise, follow your incident response plan and treat the server as breached (isolate, preserve logs, investigate).

DETECTION HINTS (quick checks)
• Check WSUS/IIS logs for unexpected POSTs to cookie/get endpoints or strange Base64/encrypted payloads.
• Look in Event Viewer for .NET application errors around WSUS service restarts or crashes.
• Scan endpoints downstream of WSUS for newly installed/modified software or unexpected connections back to unknown hosts

TECHNICAL SUMMARY (one word understanding)
CVE-2025-59287 is an unsafe-deserialization bug in WSUS’s handling of encrypted AuthorizationCookie data that lets an unauthenticated attacker send a crafted cookie which, when decrypted and deserialized, leads to remote code execution as SYSTEM. A working PoC exists, so apply Microsoft’s patch and/or isolate WSUS immediately.

Still feel you dont need an IT Support or a Cybersecurity Expert for your Business/Office? We work tirelesly so support and secure.
#capacitify #itsupport #cybercrime #cyberworld @cybersecuritynews.com

image
Like
Comment
Share
Ansa Bassey
Ansa Bassey  created a new article
7 w

Core QA Concepts and Testing Fundamentals | ##qualityassurance #qualityassurancetesting #qualityassuranceengineering

Core QA Concepts and Testing Fundamentals
Technology

Core QA Concepts and Testing Fundamentals

If software were a house, Quality Assurance (QA) would be the foundation holding everything together. You don’t see it when you admire the architecture, but without it, everything eventually cracks. Every great app, website, or platform you’ve ever loved has one thing in common: a dedicated QA process behind the scenes, ensuring it works seamlessly before you ever touch it.Whether you’re just starting your journey into QA engineering or trying to understand why testing is such a big deal in tech, this article will give you the clarity you need.
Like
Comment
Share
avatar

Ayokunle Olaniregun

 
Interesting piece
Like
· Reply · 1760957919

Delete Comment

Are you sure that you want to delete this comment ?

Grace Udoka Iyasele
Grace Udoka Iyasele  
8 w

From Beer Money to Investment Money 7 Days To Go 🍻 🔥🔥
📅 October 26, 2025
⏰ 4pm (WAT)
📍Live on Capacitify (Free Attendance)

Like
Comment
Share
Grace Udoka Iyasele
Grace Udoka Iyasele  
8 w

\From Beer Money to Investment Money\ The Clock is Ticking 🍻 🔥🔥
📅 October 26, 2025
⏰ 4pm (WAT)
📍Live on Capacitify (Free Attendance)

Like
Comment
Share
Grace Udoka Iyasele
Grace Udoka Iyasele  
8 w

8 Days to go??? Don't Miss Out😉
📅 October 26, 2025
⏰ 4pm (WAT)
📍Live on Capacitify (Free Attendance)

Like
Comment
Share
Capacitify
Capacitify  
8 w

image
Like
Comment
Share
Capacitify
Capacitify  
8 w

Join My Class Product management https://campus.capacitify.com/Product__Management

Like
Comment
Share
Grace Udoka Iyasele
Grace Udoka Iyasele  
8 w

From Suya Money to Investment Money? Let the Countdown begin🔥🔥🔥!
📅 October 26, 2025
⏰ 4pm (WAT)
📍Live on Capacitify (Free Attendance)

Like
Comment
Share
Bridget Duru
Bridget Duru  
8 w
Big ideas are everywhere.
But execution? That's where Product Mananagers shine.

Let's build what matters.
Like
Comment
Share
Showing 9 out of 15
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15

Edit Offer

Add tier








Select an image
Delete your tier
Are you sure you want to delete this tier?

Reviews

In order to sell your knowledge, content and posts, start by creating a few packages. Monetization

Pay By Wallet

Fund my Wallet

Payment Alert

You are about to purchase the items, do you want to proceed?

Request a Refund