Microsoft’s SharePoint Patch Failed To Stop Attacks
Digest more
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in an alert, said it's aware of active exploitation of CVE-2025-53770, which enables unauthenticated access to SharePoint systems and arbitrary code execution over the network.
12hon MSN
Microsoft contained a major SharePoint security flaw, amid fresh questions about the future of its legacy on-premises software.
More information has emerged on the ToolShell SharePoint zero-day attacks, including impact, victims, and threat actors.
Active SharePoint exploits since July 7 target governments and tech firms globally, risking key theft and persistent access.
Microsoft has released a critical patch for a security flaw in its SharePoint software. Hackers actively exploited this vulnerability, targeting businesses and US government agencies. The company issued the fix between July 19 and 20.
Microsoft said that critical vulnerabilities in SharePoint are being exploited by a potentially China-linked threat actor, Storm-2603, to deploy ransomware.