logo

Ransomware Actors Pile on 'ToolShell' SharePoint Bugs

ID: 6ae505d5-596f-5f22-9e71-5c9c487edbf3

STIX ID: report--6ae505d5-596f-5f22-9e71-5c9c487edbf3

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-07-24

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Microsoft reports that China-linked Storm-2603 is actively exploiting multiple on-premises SharePoint vulnerabilities (including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) to gain access, steal machine keys, and deploy Warlock ransomware; Microsoft has released patches, IoCs, and mitigation guidance and urges immediate remediation to protect unpatched SharePoint servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.