logo

Microsoft Fix Targets Attacks on SharePoint Zero-Day

ID: b44b5897-64d2-542c-b7ad-4f6fd9a1683c

STIX ID: report--b44b5897-64d2-542c-b7ad-4f6fd9a1683c

Feed Name: Krebs on Security

Threat Score
88/100

Date Published: 2025-07-21

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Microsoft released an emergency update for SharePoint Server vulnerability CVE-2025-53770 after active exploitation was observed in the wild; attackers are implanting a backdoor named ToolShell to obtain unauthenticated remote access, steal SharePoint ASP.NET machine keys, and fully access SharePoint content. CISA, Microsoft, and security researchers reported breaches affecting multiple U.S. government agencies, universities, and energy companies, and recommend immediate patching where available, enabling AMSI and Microsoft Defender AV, disconnecting vulnerable servers from the Internet, and rotating machine keys and restarting IIS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.