Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Hackers Target Microsoft SharePoint Servers in Ongoing Global Attacks
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
CybersecurityTechnology

Hackers Target Microsoft SharePoint Servers in Ongoing Global Attacks

Highlights

  • Microsoft SharePoint servers face active exploitation from a critical zero-day flaw.

  • Researchers report global impact across government, business, and infrastructure sectors.

  • Organizations are urged to act immediately, including key rotation and forensic reviews.

Kaan Demirel
Last updated: 21 July, 2025 - 9:30 pm 9:30 pm
Kaan Demirel 5 hours ago
Share
SHARE

A critical zero-day vulnerability in on-premises Microsoft SharePoint servers has fueled a surge in cyberattacks, impacting organizations across continents. The scope and rapid progression of the incident has compelled cybersecurity agencies and researchers to issue urgent warnings and guidance. Several industry sources confirm that attackers are exploiting the defect to bypass existing security measures, resulting in widespread system breaches. The fast-moving threat has raised particular concerns because similar vulnerabilities have attracted international threat actor interest in the past, occasionally leaving organizations exposed for months despite widespread alerts.

Contents
What is CVE-2025-53770 and Why is It Serious?How Are Attackers Exploiting SharePoint?Which Organizations Have Been Affected and What Measures Are Recommended?

Incidents involving Microsoft SharePoint have attracted significant attention previously, such as with the detected vulnerability CVE-2025-49706, which had prompted swift patching earlier in the month. However, the emergence of the CVE-2025-53770 issue has introduced fresh risks where prior mitigation was insufficient. Unlike older exploits, the current wave leverages more advanced methods to evade authentication protocol improvements and has quickly propagated globally. The situation is further complicated by the number of exposed SharePoint servers, with recent scans showing thousands are still at risk, similar to earlier incidents where patch adoption lagged.

What is CVE-2025-53770 and Why is It Serious?

The vulnerability, identified as CVE-2025-53770, has a maximum initial CVSS score of 9.8 and allows attackers remote, unauthenticated code execution, granting them full file access and control over internal configurations. The exploit, referred to as “ToolShell,” has already been used to intrude upon hundreds of organizations, including both governmental and private sectors. The flaw is recognized as a bypass of a previous fix for CVE-2025-49706, signaling gaps in earlier patch initiatives. Security experts noted the rapid escalation of attacks following initial scans, with exploitation moving from reconnaissance to active compromise within days.

How Are Attackers Exploiting SharePoint?

Current attack strategies involve deployment of malicious ASPX payloads via PowerShell, theft of cryptographic machine keys, and exfiltration of sensitive data. Attackers are reportedly bypassing multi-factor authentication and single sign-on features, expanding their symbolic reach beyond initial entry points.

“A compromise doesn’t stay contained — it opens the door to the entire network,”

commented Michael Sikorski, CTO and head of threat intelligence at Palo Alto Networks Unit 42, underlining the potential for lateral movement across organizational systems once a foothold is established.

Which Organizations Have Been Affected and What Measures Are Recommended?

A wide array of entities, spanning government, education, and critical infrastructure across the US, Europe, and Australia, have experienced compromise attempts. Both Eye Security and CISA pointed to large-scale exploitation, observing systemic issues in the deployment of SharePoint servers. Microsoft has advised customers to activate and configure Antimalware Scan Interface or disconnect affected servers from the internet to mitigate risk while patches are being distributed. Patching has been issued for two of the three vulnerable SharePoint versions; SharePoint Server 2016 remains unpatched as of the latest updates.

The incident exposes ongoing challenges in patch management and the pace of security improvement in large IT infrastructures. Security professionals stress the importance of rotating cryptographic keys and conducting forensic investigations beyond routine patching, given the attackers’ persistence after compromise. Real-time notification efforts are underway through collaboration among groups such as Shadowserver, Eye Security, and watchTowr, but the scale of exposure necessitates broader vigilance.

Organizations relying on on-premises Microsoft SharePoint must remain highly alert, as attackers have proven capable of adapting to and circumventing remedial actions with sophisticated techniques. Unlike previous exposures, the nature of this vulnerability enables attackers to maintain access even after traditional patching if cryptographic keys are not systematically changed. For affected organizations, isolating affected servers and promptly investigating signs of compromise are necessary steps, while monitoring ongoing advisories for updates and remediations. Data security and strict access protocols are critical, and entities operating these systems should remain cautious, as delayed response or incomplete remediation offers persistent openings for malicious actors.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Arizona Officials Criticize CISA After Election Portal Hack Exposes Security Concerns

Nordic Countries Lead Sustainable Data Center Strategies as AI Workloads Rise

Luxury Car Fans Convert Iconic Models Into Custom High-End EVs

Billionaire Foundations Launch $1 Billion Venture to Boost US Economic Mobility

Cyberattack Hits United Natural Foods, Causes $400 Million Sales Loss

Share This Article
Facebook Twitter Copy Link Print
Kaan Demirel
By Kaan Demirel
Kaan Demirel is a 28-year-old gaming enthusiast residing in Ankara. After graduating from the Statistics department of METU, he completed his master's degree in computer science. Kaan has a particular interest in strategy and simulation games and spends his free time playing competitive games and continuously learning new things about technology and game development. He is also interested in electric vehicles and cyber security. He works as a content editor at NewsLinker, where he leverages his passion for technology and gaming.
Previous Article Tesla Rolls Out Supercharger Diner in Los Angeles and Eyes Global Cities
Next Article MIT Engineers Streamline Robot Training with New 3-in-1 Interface

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

The Chinese Room Gains Independence, Sets Course for Bloodlines 2 Release
Gaming
MIT Engineers Streamline Robot Training with New 3-in-1 Interface
AI
Tesla Rolls Out Supercharger Diner in Los Angeles and Eyes Global Cities
Electric Vehicle
Tesla Robotaxi Pinpoints Passenger Location With Latest Feature
Electric Vehicle
Garmin Prepares to Launch Two New Wearable Devices
Wearables
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?