logo

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

ID: 49510fce-97e9-5401-ac46-5b8073a6ff7e

STIX ID: report--49510fce-97e9-5401-ac46-5b8073a6ff7e

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-07-21

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Infosec In Brief: Microsoft and CISA warn of active exploitation of a critical SharePoint Server zero‑day (CVE-2025-53770, CVSS 9.8) with published IOCs (IPs and POST path) and interim mitigations; additionally, Lookout reports Chinese-installed mobile surveillance malware capable of extracting data from visitors' phones, and the EFF warns Ring is restoring law‑enforcement access to devices—together these items raise immediate enterprise and traveler security concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.