Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

The Ghost in the Machine: How Digital Twins Are Taking Over the Tasks You Hate Most

Pinterest claims more searches than ChatGPT amid disappointing results

Rivian was saved by software in 2025

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75
Identity

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

userBy userJuly 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 20, 2025Ravi LakshmananZero Day/Vulnerability

Important Microsoft SharePoint flaws

Critical security vulnerabilities in Microsoft SharePoint servers have been weaponized as part of an “active and massive” exploitation campaign.

The zero-day flaw tracked as CVE-2025-53770 (CVSS score: 9.8) is described as a variant of CVE-2025-49706 (CVSS score: 6.3).

“The untrusted data descent on on-premises Microsoft SharePoint Server allows unauthorized attackers to execute code over the network,” Microsoft said in an advisory released on July 19, 2025.

The Windows manufacturer also noted that they have prepared and fully tested a comprehensive update to resolve the issue. He praised Viettel Cyber Security for discovering and reporting defects through Trend Micro’s Zero Day Initiative (ZDI).

Cybersecurity

In another alert issued Saturday, Redmond said he was aware of active attacks targeting on-premises SharePoint Server customers, but emphasized that SharePoint Online in Microsoft 365 will not be affected.

If there is no official patch, Microsoft has configured Antimalware Scan Interface (AMSI) integration in SharePoint, urging customers to deploy Defender AV on all SharePoint servers.

Please note that AMSI integration is enabled by default in the September 2023 security update for SharePoint Server 2016/2019 and the Version 23H2 feature update for SharePoint Server Subscription Edition.

For those who cannot enable AMSI, we recommend that your SharePoint server be disconnected from the Internet until security updates are available. For additional protection, users are encouraged to deploy the endpoint’s defender to detect and block post-exposure activity.

This disclosure warned of attacks that Eye Security and Palo Alto Networks Unit 42 check CVE-2025-49706 and CVE-2025-49704 (CVSS score: 8.8) and warned that it was a flaw in code injection in SharePoint. The exploit chain is called the toolshell.

However, given that CVE-2025-53770 is a “variant” of CVE-2025-49706, these attacks are suspected to be related.

Malicious activity essentially involves delivering ASPX payloads via PowerShell. Use PowerShell to steal MachineKey configurations for SharePoint Server, including VeridationKey and DecryptionKey, and maintain persistent access.

The Dutch cybersecurity company said these keys are important to generate valid __ViewState payloads and effectively convert authenticated SharePoint requests to remote code execution opportunities to gain access to them.

Cybersecurity

“We are still identifying a large amount of exploit waves,” Eye Security CTO Piet Kerkhofs told Hacker News in a statement. “This has a huge impact as it uses this remote code execution at speed and moves horizontally.”

“We identified a malicious web shell on our SharePoint servers and notified 75 compromised organizations. This group has large corporations and large government agencies all over the world.”

It is worth noting that Microsoft has not yet updated its recommendations for CVE-2025-49706 and CVE-2025-49704 to reflect active exploitation. We also contacted the company for further clarification. If you’ve heard of it, update the story.

(The story is developing. Please check again for more details.)


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMalware injected into 6 npm package after maintainer token was stolen in a phishing attack
Next Article “Battle Dragons” illuminates the lesser known constellations in the southern sky: Space Photo of the Week:
user
  • Website

Related Posts

Google reports state-sponsored hackers are using Gemini AI to support reconnaissance and attacks

February 12, 2026

Lazarus campaign plants malicious packages in npm and PyPI ecosystem

February 12, 2026

AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories

February 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Ghost in the Machine: How Digital Twins Are Taking Over the Tasks You Hate Most

Pinterest claims more searches than ChatGPT amid disappointing results

Rivian was saved by software in 2025

Musk needed a new vision for SpaceX and xAI. He landed on Moonbase Alpha.

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.