Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief (Updated July 31)
ID: 3a294ca0-ba80-50f2-9ec5-a0b758b39832
STIX ID: report--3a294ca0-ba80-50f2-9ec5-a0b758b39832
Feed Name: Palo Alto Networks Unit 42
Unit 42 reports widespread, in-the-wild exploitation of multiple critical on-premises Microsoft SharePoint vulnerabilities (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) enabling unauthenticated RCE used to install web shells, exfiltrate cryptographic MachineKeys and deliver payloads including 4L4MD4R ransomware; the brief provides IoCs, telemetry (activity timeline and targeting patterns), attribution to CL-CRI-1040/overlap with Storm-2603, and recommended mitigations and hunting queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
