logo

Microsoft SharePoint attacks ensnare 400 victims, including federal agencies

ID: 3702cfb1-928f-5990-91ac-decf1b24ffeb

STIX ID: report--3702cfb1-928f-5990-91ac-decf1b24ffeb

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-07-24

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

The report describes a multi-wave, in-the-wild exploitation campaign abusing Microsoft SharePoint zero-days (CVE-2025-53770/53771 and related flaws) that has compromised more than 400 organizations — including U.S. federal agencies and critical infrastructure — with attackers using the 'ToolShell' exploit chain to bypass MFA/SSO, deploy Warlock ransomware, and attempt cryptographic key theft; Microsoft released urgent patches and CISA initiated a national coordinated response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.