See every side of every news story
Published loading...Updated

Microsoft alerts businesses, governments to server software attack

UNITED STATES, JUL 21 – The zero-day flaw in SharePoint servers enables hackers to steal cryptographic keys and maintain access despite patches, with over 10,000 organizations at risk globally, cybersecurity experts say.

  • On July 21, 2025, Microsoft released emergency security updates for SharePoint 2019 and Subscription Edition servers, updates fully protect customers against CVE-2025-53770.
  • Researchers identified a vulnerability in on-premises SharePoint that enables remote code execution; CVE-2025-53770, dubbed ToolShell, allows unauthenticated remote code execution by bypassing MFA and SSO.
  • The exploit unfolded in two waves on July 18 and 19, Eye Security first reported the zero-day vulnerability.
  • In its Sunday statement, Cybersecurity and Infrastructure Security Agency highlighted active exploitation of the vulnerability, while noting the flaw allows malicious actors to access file systems and execute code over the network.
  • To mitigate active attacks, customers should configure Antimalware Scan Interface integration and deploy Defender AV, and if AMSI cannot be enabled, Microsoft recommended disconnecting servers from the internet.
Insights by Ground AI
Does this summary seem wrong?

273 Articles

WISNWISN
+7 Reposted by 7 other sources
Center

What to know about a vulnerability being used by hackers on Microsoft SharePoint servers

Microsoft is issuing an emergency fix to close off a vulnerability in Microsoft’s SharePoint software that hackers have exploited to carry out widespread attacks on businesses and at least some federal agencies.

·Milwaukee, United States
Read Full Article

Attackers have exploited a vulnerability in the Sharepoint software and hit targets in various countries.

·Zürich, Switzerland
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 62% of the sources are Center
62% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

IT Security News - cybersecurity, infosecurity news broke the news in on Sunday, July 20, 2025.
Sources are mostly out of (0)

You have read 1 out of your 5 free daily articles.

Join millions of well-informed readers who use Ground to compare coverage, check their news blindspots, and challenge their worldview.