From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks
ID: 408a9ba0-f1f1-5052-8853-789b470e8a2e
STIX ID: report--408a9ba0-f1f1-5052-8853-789b470e8a2e
Feed Name: Resecurity
July 2026 on-premises Microsoft SharePoint Server updates patch multiple critical vulnerabilities that CISA confirmed are actively exploited; attackers chain authentication bypasses, unauthenticated deserialization RCEs, and JWT flaws to deploy web shells, steal IIS machineKeys, forge ViewState, maintain persistence (including native IIS modules), and pivot to backend SQL/AD resources—requiring immediate patching, threat hunting for IOCs (suspicious POSTs, w3wp spawning shells, new IIS modules, stolen machineKey accesses), and AMSI/full request-body scanning, network segmentation, and remediation to remove persistence before key rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
