Tag: microsoft
-
US Nuclear Weapons Data Compromised via SharePoint Zero-Day Attack
Tags: attack, breach, china, cyber, cybersecurity, data, data-breach, exploit, government, group, hacker, hacking, infrastructure, microsoft, vulnerability, zero-dayA significant cybersecurity breach has exposed vulnerabilities in critical US government infrastructure, as the National Nuclear Security Administration (NNSA) was reportedly compromised through a Microsoft SharePoint zero-day exploit linked to Chinese government-affiliated hacking groups. Chinese Hackers Target Critical Infrastructure The breach came to light hours after Microsoft disclosed that Chinese government-affiliated hacking groups had been…
-
Microsoft patches critical SharePoint 2016 zero-days amid active exploits
Admins urged to rotate machine keys, restart IIS after emergency fix First seen on theregister.com Jump to article: www.theregister.com/2025/07/22/microsoft_sharepoint_2016_patch/
-
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks
Tags: attack, china, cisa, cve, cybersecurity, exploit, flaw, hacker, infrastructure, kev, microsoft, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on July 22, 2025, added two Microsoft SharePoint flaws, CVE-2025-49704 and CVE-2025-49706, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.To that end, Federal Civilian Executive Branch (FCEB) agencies are required to remediate identified vulnerabilities by July 23, 2025.”CISA is First seen on…
-
Microsoft Most Phished Brand in Q2 2025, Check Point Research
Microsoft was the most impersonated brand in phishing attacks during Q2 2025, accounting for 25% of all attempts, according to Check Point Research. First seen on hackread.com Jump to article: hackread.com/microsoft-most-phished-brand-q2-2025-check-point/
-
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker Groups
Microsoft has formally tied the exploitation of security flaws in internet-facing SharePoint Server instances to two Chinese hacking groups called Linen Typhoon and Violet Typhoon as early as July 7, 2025, corroborating earlier reports.The tech giant said it also observed a third China-based threat actor, which it tracks as Storm-2603, weaponizing the flaws as well…
-
Coyote Trojan First to Use Microsoft UI Automation in Bank Attacks
Coyote Trojan becomes first malware to abuse Microsoft’s UI Automation in real attacks, targeting banks and crypto platforms with stealthy tactics. First seen on hackread.com Jump to article: hackread.com/coyote-trojan-use-microsoft-ui-automation-bank-attacks/
-
Russian Threat Actors Target NGOs with New OAuth Phishing Tactics
A new wave of phishing attacks exploiting Microsoft 365 OAuth tools has been observed impersonating diplomats to steal access codes First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-hackers-target-ngos-oauth/
-
Microsoft Reveals Chinese State Hackers Exploiting SharePoint Flaws
Microsoft reveals Chinese state-backed hacker groups, including Linen Typhoon, Violet Typhoon, and Storm-2603, are exploiting SharePoint flaws, breaching over 100 organisations. Discover threat actors, their tactics and Microsoft’s urgent security guidance. First seen on hackread.com Jump to article: hackread.com/microsoft-chinese-state-hackers-exploit-sharepoint-flaws/
-
SharePoint ‘ToolShell’ Vulnerabilities Exploited by Chinese Nation-State Hackers
Microsoft has observed three China-based threat actors, Linen Typhoon, Violet Typhoon and Storm-2603, exploiting the SharePoint vulnerabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/sharepoint-toolshell-chinese/
-
Akamai Identifies Coyote Malware Variant Capable of Compromising Microsoft UIA Framework
Akamai researchers today disclosed they have discovered a variant of Coyote malware that extracts specific banking and cryptocurrency exchanges by compromising the UI Automation (UIA) framework developed by Microsoft. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/07/akamai-identifis-coyote-malware-variant-capable-of-compromising-microsoft-uia-framework/
-
Hackers Exploit Microsoft SharePoint Flaws in Global Breaches
Hackers are exploiting critical SharePoint flaws (CVE-2025-53770/53771) to breach global targets, including governments and corporations. Microsoft urges immediate action. Learn about the active attacks and how to protect your network from credential theft and backdoors. First seen on hackread.com Jump to article: hackread.com/hackers-exploit-microsoft-sharepoint-flaws-breaches/
-
US nuclear weapons agency ‘among 400 organisations breached by Chinese hackers’
Tags: business, china, cybersecurity, data-breach, exploit, government, group, hacker, microsoft, threat, vulnerabilityMicrosoft says vulnerabilities in its SharePoint servers exposed as reports point to wave of attacks<ul><li><a href=”https://www.theguardian.com/business/live/2025/jul/23/stock-markets-rally-us-japan-trade-deal-nikkei-ftse-100-libor-appeal-business-live”>Business live latest updates</li></ul><a href=”https://www.theguardian.com/technology/microsoft”>Microsoft says Chinese “threat actors”, including state-sponsored hackers, have exploited security vulnerabilities in its SharePoint document-sharing servers, with research indicating that several hundred government agencies and organisations have been breached.Hackers have already breached 400 agencies, businesses…
-
New Scanner Launched to Detect CVE-2025-53770 in SharePoint Servers
A cybersecurity researcher has released a new open-source scanner designed to detect a critical vulnerability affecting Microsoft SharePoint servers, providing organizations with a crucial tool to assess their security posture against the recently disclosed CVE-2025-53770 flaw. Rapid Response to Critical SharePoint Vulnerability Belgian cybersecurity freelancer Niels Hofmans, known by the GitHub handle >>hazcod,
-
Microsoft Sharepoint ToolShell attacks linked to Chinese hackers
Hackers with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-sharepoint-toolshell-attacks-linked-to-chinese-hackers/
-
Windows Server KB5062557 causes cluster, VM issues
Microsoft is asking businesses to reach out for support to mitigate a known issue causing Cluster service and VM restart issues after installing this month’s Windows Server 2019 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-kb5062557-causes-cluster-vm-issues/
-
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access
Tags: access, cybersecurity, exploit, government, hacker, microsoft, software, vulnerability, zero-dayThe recently disclosed critical Microsoft SharePoint vulnerability has been under exploitation as early as July 7, 2025, according to findings from Check Point Research.The cybersecurity company said it observed first exploitation attempts targeting an unnamed major Western government, with the activity intensifying on July 18 and 19, spanning government, telecommunications, and software First seen on…
-
Microsoft ‘digital escorts’ reveal crucial US counterintelligence blind spot
Tags: access, china, cio, cloud, compliance, country, cyber, cybersecurity, data, defense, firewall, framework, google, government, injection, intelligence, law, microsoft, military, oracle, risk, service, threat, update, vulnerabilityWhat the program was, and how it worked: The digital escort model, according to ProPublica, was designed to comply with federal contracting rules that prohibit foreign nationals from directly accessing sensitive government systems. Under this framework:China-based engineers would file support tickets for tasks such as firewall updates or bug fixes.US-based escorts, often former military personnel…
-
Souveräne EUDebakel: Microsoft kann US-Zugriff nicht verhindern
Da hat Microsoft einen riesigen Luftballon in Bezug auf europäische Cloud-Angebote aufgeblasen. Rechenzentren in Europa, eine “europäische Microsoft-Cloud” für digitale Souveränität. Und dann musste ein Microsoft Manager unter Eid eingestehen, dass dies nich vor dem Zugriff der US-Behörden schützt. Seit … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/22/souveraene-eu-cloud-debakel-microsoft-kann-us-zugriff-nicht-verhindern/
-
Microsoft Releases Final Patch For SharePoint Server Against ‘ToolShell’ Attacks
Microsoft released a patch Monday for SharePoint Server 2016 that protects customers against a pair of vulnerabilities, which have been widely exploited in a wave of cyberattacks known as “ToolShell.” First seen on crn.com Jump to article: www.crn.com/news/security/2025/microsoft-releases-final-patch-for-sharepoint-server-against-toolshell-attacks
-
China-Based Threat Actor Involved In Microsoft SharePoint Attacks: Mandiant CTO
Among the attackers now actively exploiting vulnerable on-premises Microsoft SharePoint servers, at least one has shown indications of originating from China, according to the assessment of researchers at Google Cloud-owned Mandiant. First seen on crn.com Jump to article: www.crn.com/news/security/2025/china-based-threat-actor-involved-in-microsoft-sharepoint-attacks-mandiant-cto
-
UK blames Russia’s infamous ‘Fancy Bear’ group for Microsoft cloud hacks
Authentic Antics malware tool to target Microsoft cloud accounts were the handiwork of the notorious Russian Fancy Bear hacking group, the UK’s National Cyber Security Centre (NCSC) has said.Authentic Antics was discovered after a cyberattack in 2023 which prompted an NCSC technical teardown of the malware that it published in May this year. The agency…
-
‘Patching Is Not Enough’ With Microsoft SharePoint Server Attacks: Experts
Microsoft is urging organizations to rotate machine keys for on-premises SharePoint Servers impacted by widely exploited critical vulnerabilities, an indicator that attackers are stealing the keys to enable further cyberattacks, according to security researchers. First seen on crn.com Jump to article: www.crn.com/news/security/2025/patching-is-not-enough-with-microsoft-sharepoint-server-attacks-experts
-
Microsoft, CISA warn of cyberattacks targeting on-premises SharePoint servers
The flaw has already led to widespread compromises prior to Microsoft’s release of an emergency patch. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-cisa-warn-cyberattacks-sharepoint/753574/
-
Patch ToolShell SharePoint zero-day immediately, says Microsoft
Active exploitation of a dangerous zero-day vulnerability chain in Microsoft SharePoint which was disclosed over the weekend is underway. Immediate action is advised. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366627866/Patch-ToolShell-SharePoint-zero-day-immediately-says-Microsoft
-
Microsoft SharePoint Server Attacks Are ‘CloseWorst-Case Scenario:’ Researcher
The “ToolShell” cyberattack campaign exploiting zero-day vulnerabilities in on-premises Microsoft SharePoint Servers has so far led to ‘widespread impact across hundreds of organizations,’ according to a researcher at cybersecurity vendor watchTowr. First seen on crn.com Jump to article: www.crn.com/news/security/2025/microsoft-sharepoint-server-attacks-are-close-to-worst-case-scenario-researcher
-
Five Things To Know On Microsoft SharePoint Server ‘ToolShell’ Attacks
An ongoing cyberattack campaign known as “ToolShell” is exploiting on-premises Microsoft SharePoint Servers and has reportedly compromised organizations worldwide. First seen on crn.com Jump to article: www.crn.com/news/security/2025/5-things-to-know-on-microsoft-sharepoint-server-toolshell-attacks
-
Microsoft Rushes Emergency Patch for Actively Exploited SharePoint ‘ToolShell’ Bug
Malicious actors already have already pounced on the zero-day vulnerability, tracked as CVE-2025-53770, to compromise US government agencies and other businesses in ongoing and widespread attacks. First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/microsoft-rushes-emergency-fix-exploited-sharepoint-toolshell-flaw
-
Hackers Exploiting Microsoft Flaw to Attack Governments, Businesses
Hackers are exploiting a significant Microsoft vulnerability chain that allows them gain control of on-premises SharePoint servers, steal cryptographic keys, and access Windows applications like Outlook, Teams, and OneDrive. It also gives them persistence in the systems even after reboots and updates. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/07/hackers-exploiting-microsoft-flaw-to-attack-governments-businesses/
-
Microsoft Confirms ‘Active Attacks’ Against SharePoint Servers, Rolls Out Emergency Patches
Microsoft confirmed “active” cyberattacks exploiting vulnerabilities in on-premises SharePoint Servers and released emergency patches for several versions of the systems. First seen on crn.com Jump to article: www.crn.com/news/security/2025/microsoft-confirms-active-attacks-against-sharepoint-servers-rolls-out-emergency-patches
-
Mass attack spree hits Microsoft SharePoint zero-day defect
Attackers have already used the exploit dubbed “ToolShell” to intrude hundreds of organizations globally, including private companies and government agencies. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-sharepoint-zero-day-attack-spree/

