Ransomware Actors Pile on 'ToolShell' SharePoint Bugs
ID: 6ae505d5-596f-5f22-9e71-5c9c487edbf3
STIX ID: report--6ae505d5-596f-5f22-9e71-5c9c487edbf3
Feed Name: Dark Reading
Threat Score
Microsoft reports that China-linked Storm-2603 is actively exploiting multiple on-premises SharePoint vulnerabilities (including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) to gain access, steal machine keys, and deploy Warlock ransomware; Microsoft has released patches, IoCs, and mitigation guidance and urges immediate remediation to protect unpatched SharePoint servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
