logo

Hackers exploiting SharePoint zero-day seen targeting government agencies

ID: 69a9393b-ee88-5ed8-a80c-ee21004c36df

STIX ID: report--69a9393b-ee88-5ed8-a80c-ee21004c36df

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2025-07-21

Date Updated: 2026-04-23

Author: Lorenzo Franceschi-Bicchierai

...
...

Researchers and CISA report a zero-day (CVE-2025-53770) in on‑premises Microsoft SharePoint is being actively exploited in the wild, with initial attacks apparently targeting government agencies, universities and critical infrastructure organizations; analysts found between 8,000–10,000 internet-accessible vulnerable SharePoint instances and warn that exploitation may expand as more attackers reuse the flaw. Microsoft advises applying patches or disconnecting affected on-prem servers from the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.