logo

New SharePoint flaws help hackers evade detection when stealing files

ID: 21e47712-f9d2-57e3-8e7b-e08bd7426ce3

STIX ID: report--21e47712-f9d2-57e3-8e7b-e08bd7426ce3

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-04-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at Varonis identified two simple techniques that let attackers bypass or downgrade SharePoint audit logs to enable stealthy data exfiltration: (1) using SharePoint's "Open in App" to generate benign "Access" events instead of "FileDownloaded", and (2) spoofing User-Agent strings (e.g., SkyDriveSync) so downloads are logged as sync events (FileSyncDownloadedFull). Both methods can be automated via PowerShell, were disclosed to Microsoft and rated moderate severity for future patching, and defenders are advised to monitor for high volumes of access, unusual device/location activity, and anomalous sync patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.