Microsoft’s SharePoint Patch Failed To Stop Attacks
Digest more
SharePoint, Microsoft
Digest more
Active SharePoint exploits since July 7 target governments and tech firms globally, risking key theft and persistent access.
A cyber-espionage campaign centred on vulnerable Microsoft software now involves the deployment of ransomware.
The department has been holding daily calls with Microsoft since the zero-day was discovered, the DOD CIO said at an event Thursday.
11hon MSN
Microsoft contained a major SharePoint security flaw, amid fresh questions about the future of its legacy on-premises software.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in an alert, said it's aware of active exploitation of CVE-2025-53770, which enables unauthenticated access to SharePoint systems and arbitrary code execution over the network.
More information has emerged on the ToolShell SharePoint zero-day attacks, including impact, victims, and threat actors.
Microsoft has released a critical patch for a security flaw in its SharePoint software. Hackers actively exploited this vulnerability, targeting businesses and US government agencies. The company issued the fix between July 19 and 20.