Parasitic Sharepoint Exploits, (Mon, Jul 28th)
ID: 510887f4-c26c-5be5-9065-f26ffaae4282
STIX ID: report--510887f4-c26c-5be5-9065-f26ffaae4282
Feed Name: SANS ISC Diary
Threat Score
The report describes active exploitation of on‑premises SharePoint vulnerabilities beginning in mid‑July 2025, with attackers dropping and later leveraging various backdoor .aspx files (notably spinstall0.aspx). Honeypot telemetry shows numerous requests and a timeline of discovered backdoor paths and first-seen dates, and Microsoft has published guidance on disrupting the exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
