Microsoft: SharePoint attacks now officially include ransomware infections
ID: 13c4c142-8a4c-5021-829f-8e578d18c302
STIX ID: report--13c4c142-8a4c-5021-829f-8e578d18c302
Feed Name: The Register (Security)
Microsoft confirmed that Storm-2603 and other groups are actively exploiting multiple patched SharePoint vulnerabilities (CVE-2025-49704, CVE-2025-49706 and related follow-ups) in internet-facing on‑premises SharePoint servers to install web shells, disable Defender, harvest credentials (Mimikatz), move laterally (PsExec, Impacket, WMI), alter GPOs and deploy Warlock/LockBit ransomware; proof-of-concept exploits are public, patches are available, and more than 400 organizations — including the US Energy Department/NNSA — have been affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
