Known Exploited Vulnerability
9.8
CRITICAL
CVE-2025-53770
Microsoft SharePoint Deserialization of Untrusted - [Actively Exploited]
Description

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

INFO

Published Date :

July 20, 2025, 1:15 a.m.

Last Modified :

July 30, 2025, 1 a.m.

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

3.9
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network.

Required Action :

CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Notes :

CISA Mitigation Instructions: https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770 ; https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/ ; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770 ; https://nvd.nist.gov/vuln/detail/CVE-2025-53770

Public PoC/Exploit Available at Github

CVE-2025-53770 has a 68 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2025-53770 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Microsoft sharepoint_server
2 Microsoft sharepoint_server_2016
3 Microsoft sharepoint_server_2019
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2025-53770.

URL Resource
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770 Vendor Advisory
https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/ Exploit Press/Media Coverage
https://github.com/kaizensecurity/CVE-2025-53770 Exploit
https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/ Mitigation Vendor Advisory
https://news.ycombinator.com/item?id=44629710 Issue Tracking
https://research.eye.security/sharepoint-under-siege/ Exploit Mitigation Third Party Advisory
https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globally Press/Media Coverage
https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/ Press/Media Coverage
https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770 Mailing List Third Party Advisory US Government Resource
https://www.darkreading.com/remote-workforce/microsoft-rushes-emergency-fix-exploited-sharepoint-toolshell-flaw Press/Media Coverage
https://www.forbes.com/sites/daveywinder/2025/07/20/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available/ Press/Media Coverage
https://x.com/Shadowserver/status/1946900837306868163 Third Party Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

SharePoint 2025 RCE Exploitation GUI

Python Ruby

Updated: 3 days, 18 hours ago
1 stars 1 fork 1 watcher
Born at : Aug. 8, 2025, 5:40 p.m. This repo has been linked 4 different CVEs too.

A comprehensive penetration testing framework with a modular architecture for security researchers, penetration testers, and ethical hackers.

Python Shell

Updated: 3 days, 23 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 8, 2025, 2:10 p.m. This repo has been linked 3 different CVEs too.

A comprehensive toolkit for searching CVE vulnerabilities across multiple sources with advanced error handling, rate limiting, and fallback strategies.

Shell Python

Updated: 3 days, 20 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 8, 2025, 10:38 a.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 4 days, 22 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 7, 2025, 3:14 p.m. This repo has been linked 1 different CVEs too.

None

Updated: 6 days, 1 hour ago
0 stars 0 fork 0 watcher
Born at : Aug. 5, 2025, 12:44 p.m. This repo has been linked 1 different CVEs too.

A critical vulnerability in Microsoft SharePoint Server allows unauthenticated remote code execution via deserialization of untrusted data. Microsoft is aware of active exploitation; apply CVE mitigations immediately. Severity: Critical.

Updated: 1 week, 3 days ago
0 stars 0 fork 0 watcher
Born at : Aug. 2, 2025, 8 a.m. This repo has been linked 1 different CVEs too.

None

C#

Updated: 1 week, 2 days ago
1 stars 0 fork 0 watcher
Born at : July 29, 2025, 2:24 p.m. This repo has been linked 1 different CVEs too.

Collection of attack flows, threat models, and detection strategies for various cybersecurity threats and vulnerabilities

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 29, 2025, 6:03 a.m. This repo has been linked 1 different CVEs too.

🎯 Vulnerability scanner for SharePoint servers affected by CVE-2025-53770. Detects unsafe deserialization using ToolPane.aspx with a crafted base64+gzip payload. 🛡️ Developed by Ahmed Tamer.

Python

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 28, 2025, 10:41 p.m. This repo has been linked 1 different CVEs too.

Valhalla API Demo - Python application demonstrating YARA and Sigma rule retrieval from Nextron Systems' Valhalla API

Python

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 28, 2025, 5:15 p.m. This repo has been linked 1 different CVEs too.

None

Python PowerShell

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 28, 2025, 3:27 p.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 2 weeks, 1 day ago
0 stars 0 fork 0 watcher
Born at : July 28, 2025, 3:39 a.m. This repo has been linked 1 different CVEs too.

CVE-2025-53770 Mass Scanner

Python

Updated: 1 week, 2 days ago
10 stars 1 fork 1 watcher
Born at : July 27, 2025, 8:55 p.m. This repo has been linked 1 different CVEs too.

An activity to train analysis skills and reporting

Updated: 2 weeks, 1 day ago
0 stars 0 fork 0 watcher
Born at : July 27, 2025, 1:58 p.m. This repo has been linked 1 different CVEs too.

Sharepoint ToolPane - PoC

sharepoint zeroday cve-2025-53770 cve-2025-53771

Python

Updated: 1 week, 6 days ago
4 stars 1 fork 1 watcher
Born at : July 26, 2025, 10:54 a.m. This repo has been linked 2 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-53770 vulnerability anywhere in the article.

  • Help Net Security
From legacy to SaaS: Why complexity is the enemy of enterprise security

In this Help Net Security interview, Robert Buljevic, Technology Consultant at Bridge IT, discusses how the coexistence of legacy systems and SaaS applications is changing the way organizations approa ... Read more

Published Date: Aug 11, 2025 (1 day, 8 hours ago)
  • Help Net Security
August 2025 Patch Tuesday forecast: Try, try, again

July turned into a surprisingly busy month. It started slowly with a fairly ‘calm’ Patch Tuesday as I forecasted in my last blog. Although there were 130 new CVEs addressed across all the Microsoft re ... Read more

Published Date: Aug 08, 2025 (4 days, 7 hours ago)
  • The Register
CISA releases malware analysis for Sharepoint Server attack

CISA has published a malware analysis report with compromise indicators and Sigma rules for "ToolShell" attacks targeting specific Microsoft SharePoint Server versions. "Cyber threat actors have chain ... Read more

Published Date: Aug 07, 2025 (4 days, 23 hours ago)
  • security.nl
VS deelt informatie over malware aangetroffen bij SharePoint-aanvallen

Het Amerikaanse cyberagentschap CISA heeft informatie gedeeld over malware die bij recente aanvallen tegen Microsoft SharePoint-servers is aangetroffen. Met de informatie kunnen organisaties kijken of ... Read more

Published Date: Aug 07, 2025 (5 days, 4 hours ago)
  • Daily CyberSecurity
CISA Warns of “ToolShell”: Critical Exploit Chain Hits SharePoint Servers, Bypasses Authentication

The Cybersecurity and Infrastructure Security Agency (CISA) has released an in-depth Malware Analysis Report warning of a sophisticated exploitation campaign targeting on-premises Microsoft SharePoint ... Read more

Published Date: Aug 07, 2025 (5 days, 13 hours ago)
  • CybersecurityNews
Chinese Hackers Exploit SharePoint Vulnerabilities to Deploy Toolsets Includes Backdoor, Ransomware and Loaders

A sophisticated Chinese threat actor has been exploiting critical vulnerabilities in Microsoft SharePoint to deploy an advanced malware toolset dubbed “Project AK47,” according to new research publish ... Read more

Published Date: Aug 06, 2025 (6 days, 3 hours ago)
  • BleepingComputer
The Heat Wasn't Just Outside: Cyber Attacks Spiked in Summer 2025

Summer 2025 wasn't just hot; it was relentless. Ransomware hammered hospitals, retail giants suffered data breaches, insurance firms were hit by phishing, and nation-state actors launched disruptive c ... Read more

Published Date: Aug 05, 2025 (1 week ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 05, 2025 (1 week ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 05, 2025 (1 week ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 04, 2025 (1 week ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • BleepingComputer
Ransomware gangs join attacks targeting Microsoft SharePoint servers

Ransomware gangs have recently joined ongoing attacks targeting a Microsoft SharePoint vulnerability chain, part of a broader exploitation campaign that has already led to the breach of at least 148 o ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • europa.eu
Cyber Brief 25-08 - July 2025

Cyber Brief (July 2025)August 4, 2025 - Version: 1TLP:CLEARExecutive summaryWe analysed 287 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, the EU, UK, and US h ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 04, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 03, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 03, 2025 (1 week, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 03, 2025 (1 week, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 03, 2025 (1 week, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 03, 2025 (1 week, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 02, 2025 (1 week, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 02, 2025 (1 week, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 02, 2025 (1 week, 3 days ago)
  • CybersecurityNews
Storm-2603 Using Custom Malware That Leverages BYOVD to Tamper with Endpoint Protections

A newly identified threat actor designated Storm-2603 has emerged as a sophisticated adversary in the ransomware landscape, leveraging advanced custom malware to circumvent endpoint security protectio ... Read more

Published Date: Aug 02, 2025 (1 week, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 3 days ago)
  • security.nl
'Ruim 800 SharePoint-servers missen update voor actief aangevallen lek'

Ruim achthonderd Microsoft SharePoint-servers die vanaf internet toegankelijk zijn, waarvan 24 in Nederland, missen een beveiligingsupdate voor een actief aangevallen kwetsbaarheid. Dat stelt The Shad ... Read more

Published Date: Aug 01, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Aug 01, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 31, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 31, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 31, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 31, 2025 (1 week, 4 days ago)
  • CybersecurityNews
17K+ SharePoint Servers Exposed to Internet – 840 Servers Vulnerable to 0-Day Attacks

A massive exposure of Microsoft SharePoint servers to internet-based attacks has been identified, with over 17,000 servers exposed and 840 specifically vulnerable to the critical zero-day vulnerabilit ... Read more

Published Date: Jul 31, 2025 (1 week, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 31, 2025 (1 week, 5 days ago)
  • nextron-systems.com
AURORA – Leveraging ETW for Advanced Threat Detection

Aurora is a lightweight endpoint agent that applies Sigma rules and IOCs directly to Windows system events reconstructed from Event Tracing for Windows (ETW). Unlike traditional logging tools or Sysmo ... Read more

Published Date: Jul 31, 2025 (1 week, 5 days ago)
  • Help Net Security
Secrets are leaking everywhere, and bots are to blame

Secrets like API keys, tokens, and credentials are scattered across messaging apps, spreadsheets, CI/CD logs, and even support tickets. According to Entro Security’s NHI & Secrets Risk Report H1 2025, ... Read more

Published Date: Jul 31, 2025 (1 week, 5 days ago)
  • AttackIQ
Response to CISA Alert: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities

On July 8, 2025, vulnerabilities CVE-2025-49704 (Remote Code Execution) and CVE-2025-49706 (Network Spoofing), affecting on-premises Microsoft SharePoint servers, were officially reported. On the same ... Read more

Published Date: Jul 30, 2025 (1 week, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 30, 2025 (1 week, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 30, 2025 (1 week, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 30, 2025 (1 week, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 30, 2025 (1 week, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 30, 2025 (1 week, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 29, 2025 (1 week, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 29, 2025 (2 weeks ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 29, 2025 (2 weeks ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 29, 2025 (2 weeks ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 28, 2025 (2 weeks ago)
  • Hot for Security
French submarine secrets surface after cyber attack

European defence giant Naval Group has confirmed that it is investigating an alleged cyber attack which has seen what purports to be sensitive internal data published on the internet by hackers.Naval ... Read more

Published Date: Jul 28, 2025 (2 weeks ago)
  • Schneier on Security
Microsoft SharePoint Zero-Day

Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to steal data worldwide: The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a po ... Read more

Published Date: Jul 28, 2025 (2 weeks, 1 day ago)
  • CybersecurityNews
New “ToolShell” Exploit Chain Attacking SharePoint Servers to Gain Complete Control

A critical new threat targeting Microsoft SharePoint servers through a sophisticated exploit chain dubbed “ToolShell.” This multi-stage attack combines previously patched vulnerabilities with fresh ze ... Read more

Published Date: Jul 28, 2025 (2 weeks, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 28, 2025 (2 weeks, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 28, 2025 (2 weeks, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 28, 2025 (2 weeks, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 28, 2025 (2 weeks, 1 day ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 27, 2025 (2 weeks, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 27, 2025 (2 weeks, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 27, 2025 (2 weeks, 2 days ago)
  • Help Net Security
Week in review: Microsoft SharePoint servers under attack, landing your first cybersecurity job

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft pins on-prem SharePoint attacks on Chinese threat actors As Microsoft continues to update it ... Read more

Published Date: Jul 27, 2025 (2 weeks, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 2 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 2 days ago)
  • The Register
Blame a leak for Microsoft SharePoint attacks, researcher insists

A week after Microsoft told the world that its July software updates didn't fully fix a couple of bugs, which allowed miscreants to take over on-premises SharePoint servers and remotely execute code, ... Read more

Published Date: Jul 26, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 26, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 3 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 3 days ago)
  • SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 30

The Good | Authorities Dismantle XSS.is Cybercrime Forum & Release Free Phobos/8Base Decryptor After a 12-year long run, XSS[.]is (formerly DaMaGeLaB) faced major disruptions this week with the arrest ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 30

The Good | Authorities Dismantle XSS.is Cybercrime Forum & Release Free Phobos/8Base Decryptor After a 12-year long run, XSS[.]is (formerly DaMaGeLaB) faced major disruptions this week with the arrest ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CybersecurityNews
Hackers Exploiting Sharepoint 0-day Vulnerability to Deploy Warlock Ransomware

Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • Kaspersky
ToolShell: a story of five vulnerabilities in Microsoft SharePoint

On July 19–20, 2025, various security companies and national CERTs published alerts about active exploitation of on-premise SharePoint servers. According to the reports, observed attacks did not requi ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 25, 2025 (2 weeks, 4 days ago)
  • CybersecurityNews
SharePoint 0-day Vulnerability Exploited in Wild by All Sorts of Hacker Groups

A critical zero-day vulnerability in Microsoft SharePoint servers has become a playground for threat actors across the cybercriminal spectrum, with attacks ranging from opportunistic hackers to sophis ... Read more

Published Date: Jul 24, 2025 (2 weeks, 4 days ago)
  • The Register
Microsoft: SharePoint attacks now officially include ransomware infections

Ransomware has officially entered the Microsoft SharePoint exploitation ring. Late Wednesday, in an update to its earlier warning, Redmond confirmed that a threat group it tracks as Storm-2603 is abus ... Read more

Published Date: Jul 24, 2025 (2 weeks, 4 days ago)
  • Help Net Security
Storm-2603 spotted deploying ransomware on exploited SharePoint servers

One of the groups that, in the past few weeks, has been exploiting vulnerabilities in on-prem SharePoint installation has been observed deploying Warlock ransomware, Microsoft shared on Wednesday. Fir ... Read more

Published Date: Jul 24, 2025 (2 weeks, 4 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Brave Browser Blocks Microsoft Recall from Tracking Online Activity

Brave browser has announced a new privacy measure, automatically blocking Microsoft’s controversial Recall feature from taking screenshots of browsing activity. This move, implemented in version 1.81 ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • The Cyber Express
Chinese Hackers Now Exploiting SharePoint Zero-Days to Deploy Warlock Ransomware: MSFT

Microsoft Threat Intelligence in an updated warning said that China-based hackers, which it tracks as Storm-2603, has quickly pivoted and now exploiting unpatched on-premise SharePoint systems to depl ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CybersecurityNews
Metasploit Module Released For Actively Exploited SharePoint 0-Day Vulnerabilities

Researchers have developed a new Metasploit exploit module targeting critical zero-day vulnerabilities in Microsoft SharePoint Server that are being actively exploited in the wild. The module, designa ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
National Nuclear Security Administration Systems Breached in SharePoint Cyberattack

A recent global cyberattack campaign, exploiting critical vulnerabilities in Microsoft’s on-premise SharePoint software, has impacted several US government agencies, including the National Institutes ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • BleepingComputer
Microsoft: SharePoint servers also targeted in ransomware attacks

A China-based hacking group is deploying Warlock ransomware on Microsoft SharePoint servers vulnerable to widespread attacks targeting the recently patched ToolShell zero-day exploit chain. "Although ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 24, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • Ars Technica
What to know about ToolShell, the SharePoint threat under mass exploitation

Active exploitation at scale Easy to exploit. Unauthenticated access. Massive reach. ToolShell has it all. Credit: Getty Images Government agencies and private industry have been under siege over the ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • The Register
Microsoft SharePoint victim count hits 400+ orgs in ongoing attacks

More than 400 organizations have been compromised in the Microsoft SharePoint attack, according to Eye Security, which initially sounded the alarm on the mass exploitation last Friday, even before Red ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • Daily CyberSecurity
Metasploit Module Released for Actively Exploited Microsoft SharePoint Flaw CVE-2025-53770

Privacy & Transparencysecurityonline.info and our partners ask for your consent to use your personal data, and to store and/or access information on your device. This includes using your personal data ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • BleepingComputer
US nuclear weapons agency hacked in Microsoft SharePoint attacks

Unknown threat actors have breached the National Nuclear Security Administration's network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA is a semi-au ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • BleepingComputer
US nuclear weapons agency reportedly hacked in SharePoint attacks

Unknown threat actors have reportedly breached the National Nuclear Security Administration's network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA i ... Read more

Published Date: Jul 23, 2025 (2 weeks, 5 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • Help Net Security
Maximum severity Cisco ISE vulnerabilities exploited by attackers

One or more vulnerabilities affecting Cisco Identity Services Engine (ISE) are being exploited in the wild, Cisco has confirmed by updating the security advisory for the flaws. About the vulnerabiliti ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • CybersecurityNews
CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation

CISA has issued an urgent alert regarding active exploitation of critical Microsoft SharePoint vulnerabilities by suspected Chinese threat actors. The attack campaign, dubbed “ToolShell,” leverages a ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • security.nl
SharePoint-servers Amerikaans ministerie getroffen door aanval

SharePoint-servers van het Amerikaanse ministerie van Energie zijn afgelopen vrijdag getroffen door een aanval, zo laat een woordvoerder tegenover persbureau Bloomberg weten. Een anonieme bron stelt d ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • CybersecurityNews
CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild

CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild. The vulnerabilities, designated as CVE-2025-49704 ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Initial SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • CybersecurityNews
Chinese Hackers Actively Exploiting SharePoint Servers 0-Day Flaw in the Wild

Microsoft has confirmed that Chinese state-sponsored threat actors are actively exploiting critical zero-day vulnerabilities in on-premises SharePoint servers, prompting urgent security warnings for o ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • The Hacker News
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

Jul 23, 2025Ravie LakshmananVulnerability / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on July 22, 2025, added two Microsoft SharePoint flaws, CVE-2025-497 ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • SentinelOne
More From Our Main Blog: Defending Against ToolShell: SharePoint’s Latest Critical Vulnerability

A new, critical zero-day vulnerability dubbed “ToolShell” (CVE-2025-53770) poses a significant threat to on-premises SharePoint Server deployments. This vulnerability enables unauthenticated remote co ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • SentinelOne
More From Our Main Blog: Defending Against ToolShell: SharePoint’s Latest Critical Vulnerability

A new, critical zero-day vulnerability dubbed “ToolShell” (CVE-2025-53770) poses a significant threat to on-premises SharePoint Server deployments. This vulnerability enables unauthenticated remote co ... Read more

Published Date: Jul 23, 2025 (2 weeks, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Widespread SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Widespread SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Microsoft Reveals Chinese State Hackers Exploiting SharePoint Flaws

Microsoft’s critical new update reveals that specific Chinese nation-state threat groups are actively exploiting vulnerabilities in its on-premises SharePoint servers. Following an earlier report from ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • The Register
Surprise, surprise: Chinese spies, IP stealers, other miscreants attacking Microsoft SharePoint servers

At least three Chinese groups are attacking on-premises SharePoint servers via a couple of recently disclosed Microsoft bugs, according to Redmond. Two of the crews behind the zero-day attacks are gov ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • The Cloudflare Blog
Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770

2025-07-223 min readOn July 19, 2025, Microsoft disclosed CVE-2025-53770, a critical zero-day Remote Code Execution (RCE) vulnerability. Assigned a CVSS 3.1 base score of 9.8 (Critical), the vulnerabi ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • cybereason.com
CVE-2025-53770 & CVE-2025-53771: Critical On-Prem SharePoint Vulnerabilities

Cybereason is actively investigating exploitation of these vulnerabilities. Check the Cybereason blog for additional updates. Key Takeaways Two zero-day vulnerabilities discovered in on-premise Micros ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • The Hacker News
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups

Jul 22, 2025Ravie LakshmananVulnerability / Threat Intelligence Microsoft has formally tied the exploitation of security flaws in internet-facing SharePoint Server instances to two Chinese hacking g ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Widespread SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • Help Net Security
Microsoft pins on-prem SharePoint attacks on Chinese threat actors

As Microsoft continues to update its customer guidance for protecting on-prem SharePoint servers against the latest in-the-wild attacks, more security firms have begun sharing details about the ones t ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • The Register
Microsoft patches critical SharePoint 2016 zero-days amid active exploits

Microsoft has good news for administrators running SharePoint Server 2016. The cloud and software megacorp has published updates to close a gaping hole in the document management service. What's parti ... Read more

Published Date: Jul 22, 2025 (2 weeks, 6 days ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Widespread SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • CybersecurityNews
New Scanner Released to Detect SharePoint Servers Vulnerable to 0-Day Attack

An open-source scanning tool has been released to identify SharePoint servers vulnerable to the critical zero-day exploit CVE-2025-53770. The newly published scanner, available on GitHub, enables orga ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • security.nl
Microsoft: meerdere statelijke actoren misbruiken SharePoint-lekken

Meerder statelijke actoren maken actief misbruik van kwetsbaarheden in SharePoint, zo claimt Microsoft vandaag. De aanvallen zouden mogelijk al sinds 7 juli plaatsvinden. Daarbij werd in eerste instan ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Hackers Exploit Microsoft SharePoint Flaws in Global Breaches

New information has emerged regarding ongoing cyberattacks against Microsoft’s on-premises SharePoint servers, revealing a wider impact than initially understood. Yesterday, Hackread.com reported on M ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • BleepingComputer
Microsoft Sharepoint ToolShell attacks linked to Chinese hackers

Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. They used this exploit ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • security.nl
Microsoft dicht actief aangevallen lek ook in SharePoint Server 2016

Microsoft heeft een actief aangevallen kwetsbaarheid ook in SharePoint Server 2016 verholpen. Afgelopen zondag verschenen er al beveiligingsupdates voor SharePoint Server 2019 en SharePoint Subscripti ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • The Hacker News
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access

The recently disclosed critical Microsoft SharePoint vulnerability has been under exploitation as early as July 7, 2025, according to findings from Check Point Research. The cybersecurity company said ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • CrowdStrike.com
CrowdStrike Detects and Blocks Widespread SharePoint Zero-Day Exploitation

Beginning on July 18, 2025, at approximately 0700 UTC, CrowdStrike Falcon® Complete Next-Gen MDR and CrowdStrike Falcon® Adversary OverWatch™ identified a wave of Microsoft SharePoint exploitation att ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • CybersecurityNews
Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. M ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • Trend Micro
Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)

Exploits & Vulnerabilities CVE-2025-53770 and CVE-2025-53771 are vulnerabilities in on-premise Microsoft SharePoint Servers that evolved from previously patched flaws, allowing unauthenticated remote ... Read more

Published Date: Jul 22, 2025 (3 weeks ago)
  • SentinelOne
More From Our Main Blog: SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers

On July 19th, Microsoft confirmed that a 0-day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell” (by researcher Khoa Dinh @_l0gg), was being actively exploited in th ... Read more

Published Date: Jul 21, 2025 (3 weeks ago)
  • SentinelOne
More From Our Main Blog: SharePoint ToolShell | Zero-Day Exploited in-the-Wild Targets Enterprise Servers

On July 19th, Microsoft confirmed that a 0-day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell” (by researcher Khoa Dinh @_l0gg), was being actively exploited in th ... Read more

Published Date: Jul 21, 2025 (3 weeks ago)
  • The Register
Another massive security snafu hits Microsoft, but don't expect it to stick

comment Here we go again. Another major Microsoft attack, with this one seeing someone — most likely government-backed hackers — exploiting a zero-day bug in SharePoint Server that Redmond failed to f ... Read more

Published Date: Jul 21, 2025 (3 weeks ago)
  • Ars Technica
SharePoint vulnerability with 9.8 severity rating under exploit across globe

ASSUME COMPROMISE Ongoing attacks are allowing hackers to steal credentials giving privileged access. Authorities and researchers are sounding the alarm over the active mass exploitation of a high-sev ... Read more

Published Date: Jul 21, 2025 (3 weeks ago)
  • krebsonsecurity.com
Microsoft Fix Targets Attacks on SharePoint Zero-Day

On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch come ... Read more

Published Date: Jul 21, 2025 (3 weeks ago)
  • Kaspersky
Update Microsoft SharePoint ASAP | Kaspersky official blog

Unknown malefactors are actively attacking companies that use SharePoint Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. By exploiting a chain of two vulnerabilities – ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • CybersecurityNews
CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild

CISA has issued an urgent warning about a critical zero-day remote code execution vulnerability affecting Microsoft SharePoint Server on-premises installations that threat actors are actively exploiti ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
Microsoft Confirms Hackers Exploiting SharePoint Flaws, Patch Now

Microsoft has released new security updates to fix two serious vulnerabilities affecting on-premises SharePoint servers, warning that attackers are already exploiting them in active campaigns. The vul ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • The Register
Microsoft patches under-attack SharePoint 2019 and SE

Microsoft is releasing out-of-band security updates for SharePoint Server 2019 and SharePoint Server Subscription Edition, following a warning that vulnerable versions were now under attack. If AMSI c ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • CybersecurityNews
Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability

Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting. The vulnerabilities, assigned as ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • security.nl
NCSC en Microsoft waarschuwen voor actief misbruik van SharePoint-lek

maandag 21 juli 2025, 09:24 door Redactie, 18 reactiesLaatst bijgewerkt: Gisteren, 16:40 Het Nationaal Cyber Security Centrum (NCSC), Microsoft en het Amerikaanse cyberagentschap CISA waarschuwen voor ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • The Cyber Express
Zero-Day Vulnerability Hits Microsoft SharePoint, Urgent Patch Issued

Microsoft has issued a warning about active cyberattacks targeting on-premises SharePoint servers widely used by government agencies and businesses. The cyberattacks exploit a zero-day vulnerability t ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • BleepingComputer
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks

Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in "ToolShell" attac ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • The Hacker News
Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks

Microsoft on Sunday released security patches for an actively exploited security flaw in SharePoint and also released details of another vulnerability that it said has been addressed with "more robust ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • TheCyberThrone
CISA adds CVE-2025-53770 SharePoint Vulnerability to KEV

July 21, 2025SummaryA critical remote code execution (RCE) vulnerability has been discovered in Microsoft SharePoint Server (on-premises versions only). The vulnerability, tracked as CVE-2025-53770, a ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • Daily CyberSecurity
ToolShell: New SharePoint RCE Zero-Day Chain Under Active Global Exploitation

Image: CODE WHITE GmbH On the evening of July 18, 2025, Eye Security identified an active, large-scale exploitation of a newly discovered Microsoft SharePoint remote code execution (RCE) vulnerability ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • The Register
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

Infosec In Brief Microsoft has warned users of SharePoint Server that three on-prem versions of the product include a zero-day flaw that is under attack – and that its own failure to completely fix pa ... Read more

Published Date: Jul 21, 2025 (3 weeks, 1 day ago)
  • Help Net Security
Microsoft SharePoint servers under attack via zero-day vulnerability with no patch (CVE-2025-53770)

Attackers are exploiting a zero-day variant (CVE-2025-53770) of a SharePoint remote code execution vulnerability (CVE-2025-49706) that Microsoft patched earlier this month, the company has confirmed o ... Read more

Published Date: Jul 20, 2025 (3 weeks, 1 day ago)
  • CybersecurityNews
Weekly Cybersecurity Newsletter: Chrome 0-Day, VMware Flaws Patched, Fortiweb Hack, Teams Abuse, and More

It’s been a busy seven days for security alerts. Google is addressing another actively exploited zero-day in Chrome, and VMware has rolled out key patches for its own set of vulnerabilities. We’ll als ... Read more

Published Date: Jul 20, 2025 (3 weeks, 1 day ago)
  • BleepingComputer
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, has been actively exploited since at least July 18th, with no patch available and at least 85 servers already comp ... Read more

Published Date: Jul 20, 2025 (3 weeks, 1 day ago)
  • The Hacker News
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Global Organizations

Jul 20, 2025Ravie LakshmananZero-Day / Vulnerability A critical security vulnerability in Microsoft SharePoint Server has been weaponized as part of an "active, large-scale" exploitation campaign. T ... Read more

Published Date: Jul 20, 2025 (3 weeks, 2 days ago)
  • CybersecurityNews
SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access

A sophisticated cyberattack campaign targeting Microsoft SharePoint servers has been discovered exploiting a newly weaponized vulnerability chain dubbed “ToolShell,” enabling attackers to gain complet ... Read more

Published Date: Jul 20, 2025 (3 weeks, 2 days ago)
  • Daily CyberSecurity
SharePoint Server Under Active Zero-Day Attack (CVE-2025-53770, CVSS 9.8), No Patch Yet!

Microsoft has issued an urgent security advisory for on-premises SharePoint Server customers in response to active exploitation of a critical remote code execution (RCE) vulnerability. The issue—now t ... Read more

Published Date: Jul 20, 2025 (3 weeks, 2 days ago)

The following table lists the changes that have been made to the CVE-2025-53770 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Jul. 30, 2025

    Action Type Old Value New Value
    Changed Required Action CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
  • Modified Analysis by [email protected]

    Jul. 23, 2025

    Action Type Old Value New Value
    Added Reference Type CVE: https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/ Types: Exploit, Press/Media Coverage
    Added Reference Type CVE: https://news.ycombinator.com/item?id=44629710 Types: Issue Tracking
    Added Reference Type CVE: https://www.darkreading.com/remote-workforce/microsoft-rushes-emergency-fix-exploited-sharepoint-toolshell-flaw Types: Press/Media Coverage
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Jul. 22, 2025

    Action Type Old Value New Value
    Added Reference https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/
    Added Reference https://www.darkreading.com/remote-workforce/microsoft-rushes-emergency-fix-exploited-sharepoint-toolshell-flaw
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Jul. 22, 2025

    Action Type Old Value New Value
    Added Reference https://news.ycombinator.com/item?id=44629710
  • Initial Analysis by [email protected]

    Jul. 21, 2025

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.18526.20508
    Added Reference Type CVE: https://github.com/kaizensecurity/CVE-2025-53770 Types: Exploit
    Added Reference Type CVE: https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/ Types: Mitigation, Vendor Advisory
    Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770 Types: Vendor Advisory
    Added Reference Type CVE: https://research.eye.security/sharepoint-under-siege/ Types: Exploit, Mitigation, Third Party Advisory
    Added Reference Type CVE: https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globally Types: Press/Media Coverage
    Added Reference Type CVE: https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/ Types: Press/Media Coverage
    Added Reference Type CVE: https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770 Types: Mailing List, Third Party Advisory, US Government Resource
    Added Reference Type CVE: https://www.forbes.com/sites/daveywinder/2025/07/20/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available/ Types: Press/Media Coverage
    Added Reference Type CVE: https://x.com/Shadowserver/status/1946900837306868163 Types: Third Party Advisory
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Jul. 21, 2025

    Action Type Old Value New Value
    Added Reference https://github.com/kaizensecurity/CVE-2025-53770
    Added Reference https://therecord.media/microsoft-sharepoint-zero-day-vulnerability-exploited-globally
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Jul. 21, 2025

    Action Type Old Value New Value
    Added Date Added 2025-07-20
    Added Due Date 2025-07-21
    Added Required Action CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
    Added Vulnerability Name Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Jul. 21, 2025

    Action Type Old Value New Value
    Added Reference https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
    Added Reference https://research.eye.security/sharepoint-under-siege/
    Added Reference https://www.bleepingcomputer.com/news/microsoft/microsoft-sharepoint-zero-day-exploited-in-rce-attacks-no-patch-available/
    Added Reference https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770
    Added Reference https://www.forbes.com/sites/daveywinder/2025/07/20/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available/
    Added Reference https://x.com/Shadowserver/status/1946900837306868163
  • New CVE Received by [email protected]

    Jul. 20, 2025

    Action Type Old Value New Value
    Added Description Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-502
    Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-53770 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-53770 weaknesses.

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability