Cato CTRL™ Threat Brief: “ToolShell” Exploit Targeting Microsoft SharePoint Vulnerabilities
ID: 1e797385-1c34-5daa-ac42-fd47179a3088
STIX ID: report--1e797385-1c34-5daa-ac42-fd47179a3088
Feed Name: Cato Networks
Threat Score
On July 22, 2025 Microsoft disclosed a chain of critical SharePoint Server vulnerabilities being actively exploited via a multi-stage exploit dubbed "ToolShell," which achieves unauthenticated RCE, deploys web shells, exfiltrates cryptographic keys, and enables persistent signed payload execution; Microsoft observed exploitation by two named Chinese nation-state actors and issued emergency updates while Cato describes SASE/XDR protections to detect and block exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
