Microsoft Fix Targets Attacks on SharePoint Zero-Day
ID: b44b5897-64d2-542c-b7ad-4f6fd9a1683c
STIX ID: report--b44b5897-64d2-542c-b7ad-4f6fd9a1683c
Feed Name: Krebs on Security
Microsoft released an emergency update for SharePoint Server vulnerability CVE-2025-53770 after active exploitation was observed in the wild; attackers are implanting a backdoor named ToolShell to obtain unauthenticated remote access, steal SharePoint ASP.NET machine keys, and fully access SharePoint content. CISA, Microsoft, and security researchers reported breaches affecting multiple U.S. government agencies, universities, and energy companies, and recommend immediate patching where available, enabling AMSI and Microsoft Defender AV, disconnecting vulnerable servers from the Internet, and rotating machine keys and restarting IIS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
