Tag: zero-day
-
Sharepoint Server 0-Day-Schwachstelle: über 400 Opfer, WarlockInfektionen
Langsam wird das Ausmaß der beobachteten Angriffswelle auf 0-Day-Schwachstellen in Microsoft SharePoint sichtbar. Microsoft hat inzwischen zwar Notfall-Updates für SharePoint Server freigegeben. Mittlerweile ist aber bekannt, dass über 400 Organisation wohl kompromittiert wurden. Und es steht fest, dass Angreifer die … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/25/sharepoint-server-0-day-schwachstelle-ueber-400-opfer-warlock-ransomware-infektionen/
-
Patches und erste Untersuchungserbenisse – 0-Day in SharePoint wird weltweit für Angriffe genutzt
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sharepoint-schwachstelle-bedroht-globale-unternehmen-a-1475b3207bad33faa687edade219fa82/
-
Patches und erste Untersuchungserbenisse – 0-Day in SharePoint wird weltweit für Angriffe genutzt
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sharepoint-schwachstelle-bedroht-globale-unternehmen-a-1475b3207bad33faa687edade219fa82/
-
U.S. CISA urges FCEB agencies to fix two Microsoft SharePoint flaws immediately and added them to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds two Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This week, Microsoft warned of a SharePoint zero-day vulnerability, tracked as…
-
Patch für Sharepoint Server 2016; China hinter Angriffen, ca. 400 Organisationen kompromittiert
Noch ein Nachtrag zur 0-Day-Schwachstelle in Microsoft SharePoint sowie der beobachteten Angriffswelle. Microsoft hat auch für SharePoint Server 2016 ein Notfall-Update freigegeben. Inzwischen gibt es Meldungen, dass ein Teil der Angriffe über einen 0-day-Exploit aus China kamen. Und über 400 … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/22/patch-fuer-sharepoint-server-2016-china-hinter-angriffen-ca-100-organisationen-kompromittiert/
-
US Nuclear Agency Hacked in Microsoft SharePoint Frenzy
Threat actors are piling on the zero-day vulnerabilities in SharePoint, including at least three Chinese nation-state cyber-espionage groups. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/us-nuclear-agency-hacked-microsoft-sharepoint
-
US nuclear weapons agency hacked in Microsoft SharePoint attacks
Unknown threat actors have breached the National Nuclear Security Administration’s network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-nuclear-weapons-agency-hacked-in-microsoft-sharepoint-attacks/
-
US Nuclear Weapons Data Compromised via SharePoint Zero-Day Attack
Tags: attack, breach, china, cyber, cybersecurity, data, data-breach, exploit, government, group, hacker, hacking, infrastructure, microsoft, vulnerability, zero-dayA significant cybersecurity breach has exposed vulnerabilities in critical US government infrastructure, as the National Nuclear Security Administration (NNSA) was reportedly compromised through a Microsoft SharePoint zero-day exploit linked to Chinese government-affiliated hacking groups. Chinese Hackers Target Critical Infrastructure The breach came to light hours after Microsoft disclosed that Chinese government-affiliated hacking groups had been…
-
Hacker aus China nutzen neue Sharepoint-Lücke aus
Microsoft hat drei chinesische Hackergruppen identifiziert, die für die Angriffe über die Sicherheitslücke in SharePoint verantwortlich sein sollen.Bei den aktuellen Cyberattacken auf zahlreiche Unternehmen und Behörden führt die Spur Microsoft zufolge nach China. Unter den Angreifern seien bisher drei chinesische Hackergruppen identifiziert worden, teilte der Software-Konzern mit. Zwei davon seien für Aktionen im staatlichen Auftrag…
-
Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups
Linen Typhoon, Violet Typhoon and Storm-2603 are behind the initial attack spree that erupted over the weekend. Other threat groups are now following suit. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-sharepoint-zero-days-china-typhoon/
-
Microsoft SharePoint On-Premise Vulnerability (CVE-2025-53770) Under Active Exploitation
Summary A critical zero-day vulnerability (now assigned CVE-2025-53770) has been identified in Microsoft SharePoint Server, affecting multiple on-premises versions. The flaw allows unauthenticated remote code First seen on research.kudelskisecurity.com Jump to article: research.kudelskisecurity.com/2025/07/23/microsoft-sharepoint-on-premise-vulnerability-cve-2025-53770-under-active-exploitation/
-
Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day
The tech giants have evidence that Chinese hackers are exploiting the new bug, but warned “multiple actors” are also hacking into affected SharePoint systems. First seen on techcrunch.com Jump to article: techcrunch.com/2025/07/22/google-microsoft-say-chinese-hackers-are-exploiting-sharepoint-zero-day/
-
Patch für Sharepoint Server 2016; China hinter Angriffen, ca. 100 Organisationen kompromittiert
Noch ein Nachtrag zur 0-Day-Schwachstelle in Microsoft SharePoint sowie der beobachteten Angriffswelle. Microsoft hat auch für SharePoint Server 2016 ein Notfall-Update freigegeben. Inzwischen gibt es Meldungen, dass ein Teil der Angriffe über einen 0-day-Exploit aus China kamen. Und über 100 … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/07/22/patch-fuer-sharepoint-server-2016-china-hinter-angriffen-ca-100-organisationen-kompromittiert/
-
Microsoft patches critical SharePoint 2016 zero-days amid active exploits
Admins urged to rotate machine keys, restart IIS after emergency fix First seen on theregister.com Jump to article: www.theregister.com/2025/07/22/microsoft_sharepoint_2016_patch/
-
SharePoint under fire: new ToolShell attacks target enterprises
While SentinelOne did not attribute the attack to a specific threat actor, The Washington Post linked it to China-nexus acors. On July 19, Microsoft confirmed active exploitation of a zero-day vulnerability, tracked as CVE-2025-53770 in on-prem SharePoint Servers. The IT giant issued emergency patches for SharePoint Subscription Edition and 2019, with 2016 updates pending. Microsoft…
-
US Nuclear Agency Breach Tied to SharePoint Zero-Days
Over 400 Organizations Breached via Ongoing ToolShell Attacks, Researchers Warn. The U.S. government agency that maintains and designs America’s nuclear weapons was reportedly breached by attackers exploiting zero-day flaws in on-premises Microsoft SharePoint servers, with researchers now counting over 400 victims, including European and Middle Eastern governments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/us-nuclear-agency-breach-tied-to-sharepoint-zero-days-a-29037
-
Chinese cyber spies among those linked to SharePoint attacks
Exploitation of the ToolShell RCE zero-day in Microsoft SharePoint continues to gather pace, with evidence emerging of exploitation by nation state-backed threat actors First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366627767/Chinese-cyber-spies-among-those-linked-to-SharePoint-attacks
-
Hackers Selling macOS 0-Day LPE Exploit on Dark Forums
A threat actor claiming to possess a zero-day Local Privilege Escalation (LPE) exploit targeting Apple’s macOS operating system has emerged on underground cybercriminal forums, offering the vulnerability for sale at a substantial price point. The alleged exploit, if genuine, represents a significant security concern for macOS users across multiple operating system versions, potentially allowing attackers…
-
CrushFTP zero-day actively exploited at least since July 18
Hackers exploit CrushFTP zero-day, tracked as CVE-2025-54309, to gain admin access via HTTPS when DMZ proxy is off. Threat actors are exploiting a zero-day vulnerability, tracked as CVE-2025-54309 (CVSS score of 9.0), in the managed file transfer software CrushFTP to gain administrative privileges on vulnerable servers via HTTPS. CrushFTP warned of a zero-day that has…
-
Microsoft Sharepoint ToolShell attacks linked to Chinese hackers
Hackers with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-sharepoint-toolshell-attacks-linked-to-chinese-hackers/
-
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access
Tags: access, cybersecurity, exploit, government, hacker, microsoft, software, vulnerability, zero-dayThe recently disclosed critical Microsoft SharePoint vulnerability has been under exploitation as early as July 7, 2025, according to findings from Check Point Research.The cybersecurity company said it observed first exploitation attempts targeting an unnamed major Western government, with the activity intensifying on July 18 and 19, spanning government, telecommunications, and software First seen on…
-
FBI ermittelt – 0-Day in SharePoint wird weltweit für Angriffe genutzt
First seen on security-insider.de Jump to article: www.security-insider.de/kritische-sharepoint-schwachstelle-bedroht-globale-unternehmen-a-1475b3207bad33faa687edade219fa82/
-
File transfer company CrushFTP warns of zero-day exploit seen in the wild
The popular file transfer company CrushFTP has discovered a previously unknown vulnerability being exploited by hackers. First seen on therecord.media Jump to article: therecord.media/file-transfer-crushftp-zero-day
-
File Transfer Flaw Blamed in Health Breach Affecting 233,000
Cierant Corp. Says Cleo MFT Zero-Day Exploit Compromised Health Plan Client Data. A Connecticut-based firm that provides print and electronic document management services to health plans has reported to regulators that an exploit of a vulnerability in file transfer software from third-party vendor Cleo has resulted in a health data compromise affecting nearly 233,000 people.…
-
Hackers exploiting SharePoint zero-day seen targeting government agencies
Thousands of SharePoint servers could be vulnerable to hackers, according to cybersecurity firms. First seen on techcrunch.com Jump to article: techcrunch.com/2025/07/21/hackers-exploiting-sharepoint-zero-day-seen-targeting-government-agencies-say-researchers/
-
Hackers Target Zero-Day Vulnerability to Exploit CrushFTP
Attackers Modify File-Transfer Server Software to Display Patched Version Number. Managed file-transfer software developer CrushFTP said a zero-day vulnerability in its tool’s web interface is being actively exploited to gain admin-level access to servers. The company urged immediate updating, saying all versions of its software released since July 1 are patched. First seen on govinfosecurity.com…
-
Patch ToolShell SharePoint zero-day immediately, says Microsoft
Active exploitation of a dangerous zero-day vulnerability chain in Microsoft SharePoint which was disclosed over the weekend is underway. Immediate action is advised. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366627866/Patch-ToolShell-SharePoint-zero-day-immediately-says-Microsoft
-
Microsoft SharePoint Server Attacks Are ‘CloseWorst-Case Scenario:’ Researcher
The “ToolShell” cyberattack campaign exploiting zero-day vulnerabilities in on-premises Microsoft SharePoint Servers has so far led to ‘widespread impact across hundreds of organizations,’ according to a researcher at cybersecurity vendor watchTowr. First seen on crn.com Jump to article: www.crn.com/news/security/2025/microsoft-sharepoint-server-attacks-are-close-to-worst-case-scenario-researcher
-
Mass attack spree hits Microsoft SharePoint zero-day defect
Attackers have already used the exploit dubbed “ToolShell” to intrude hundreds of organizations globally, including private companies and government agencies. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-sharepoint-zero-day-attack-spree/
-
Microsoft Rushes Emergency Patch for Actively Exploited SharePoint ‘ToolShell’ Bug
Malicious actors already have already pounced on the zero-day vulnerability, tracked as CVE-2025-53770, to compromise US government agencies and other businesses in ongoing and widespread attacks. First seen on darkreading.com Jump to article: www.darkreading.com/remote-workforce/microsoft-rushes-emergency-fix-exploited-sharepoint-toolshell-flaw

