Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75
Identity

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

userBy userJuly 20, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 20, 2025Ravi LakshmananZero Day/Vulnerability

Important Microsoft SharePoint flaws

Critical security vulnerabilities in Microsoft SharePoint servers have been weaponized as part of an “active and massive” exploitation campaign.

The zero-day flaw tracked as CVE-2025-53770 (CVSS score: 9.8) is described as a variant of CVE-2025-49706 (CVSS score: 6.3).

“The untrusted data descent on on-premises Microsoft SharePoint Server allows unauthorized attackers to execute code over the network,” Microsoft said in an advisory released on July 19, 2025.

The Windows manufacturer also noted that they have prepared and fully tested a comprehensive update to resolve the issue. He praised Viettel Cyber Security for discovering and reporting defects through Trend Micro’s Zero Day Initiative (ZDI).

Cybersecurity

In another alert issued Saturday, Redmond said he was aware of active attacks targeting on-premises SharePoint Server customers, but emphasized that SharePoint Online in Microsoft 365 will not be affected.

If there is no official patch, Microsoft has configured Antimalware Scan Interface (AMSI) integration in SharePoint, urging customers to deploy Defender AV on all SharePoint servers.

Please note that AMSI integration is enabled by default in the September 2023 security update for SharePoint Server 2016/2019 and the Version 23H2 feature update for SharePoint Server Subscription Edition.

For those who cannot enable AMSI, we recommend that your SharePoint server be disconnected from the Internet until security updates are available. For additional protection, users are encouraged to deploy the endpoint’s defender to detect and block post-exposure activity.

This disclosure warned of attacks that Eye Security and Palo Alto Networks Unit 42 check CVE-2025-49706 and CVE-2025-49704 (CVSS score: 8.8) and warned that it was a flaw in code injection in SharePoint. The exploit chain is called the toolshell.

However, given that CVE-2025-53770 is a “variant” of CVE-2025-49706, these attacks are suspected to be related.

Malicious activity essentially involves delivering ASPX payloads via PowerShell. Use PowerShell to steal MachineKey configurations for SharePoint Server, including VeridationKey and DecryptionKey, and maintain persistent access.

The Dutch cybersecurity company said these keys are important to generate valid __ViewState payloads and effectively convert authenticated SharePoint requests to remote code execution opportunities to gain access to them.

Cybersecurity

“We are still identifying a large amount of exploit waves,” Eye Security CTO Piet Kerkhofs told Hacker News in a statement. “This has a huge impact as it uses this remote code execution at speed and moves horizontally.”

“We identified a malicious web shell on our SharePoint servers and notified 75 compromised organizations. This group has large corporations and large government agencies all over the world.”

It is worth noting that Microsoft has not yet updated its recommendations for CVE-2025-49706 and CVE-2025-49704 to reflect active exploitation. We also contacted the company for further clarification. If you’ve heard of it, update the story.

(The story is developing. Please check again for more details.)


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMalware injected into 6 npm package after maintainer token was stolen in a phishing attack
user
  • Website

Related Posts

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

July 20, 2025

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

July 20, 2025

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

July 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

Astronomer CEO resigns following Cold Play Concert Scandal

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.