logo

Parasitic Sharepoint Exploits, (Mon, Jul 28th)

ID: 510887f4-c26c-5be5-9065-f26ffaae4282

STIX ID: report--510887f4-c26c-5be5-9065-f26ffaae4282

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2025-07-28

Date Updated: 2026-04-19

...
...

The report describes active exploitation of on‑premises SharePoint vulnerabilities beginning in mid‑July 2025, with attackers dropping and later leveraging various backdoor .aspx files (notably spinstall0.aspx). Honeypot telemetry shows numerous requests and a timeline of discovered backdoor paths and first-seen dates, and Microsoft has published guidance on disrupting the exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.