Microsoft alerts businesses, governments to server software attack
UNITED STATES, JUL 21 – The zero-day flaw in SharePoint servers enables hackers to steal cryptographic keys and maintain access despite patches, with over 10,000 organizations at risk globally, cybersecurity experts say.
- On July 21, 2025, Microsoft released emergency security updates for SharePoint 2019 and Subscription Edition servers, updates fully protect customers against CVE-2025-53770.
- Researchers identified a vulnerability in on-premises SharePoint that enables remote code execution; CVE-2025-53770, dubbed ToolShell, allows unauthenticated remote code execution by bypassing MFA and SSO.
- The exploit unfolded in two waves on July 18 and 19, Eye Security first reported the zero-day vulnerability.
- In its Sunday statement, Cybersecurity and Infrastructure Security Agency highlighted active exploitation of the vulnerability, while noting the flaw allows malicious actors to access file systems and execute code over the network.
- To mitigate active attacks, customers should configure Antimalware Scan Interface integration and deploy Defender AV, and if AMSI cannot be enabled, Microsoft recommended disconnecting servers from the internet.
273 Articles
273 Articles
What to know about a vulnerability being used by hackers on Microsoft SharePoint servers
Microsoft is issuing an emergency fix to close off a vulnerability in Microsoft’s SharePoint software that hackers have exploited to carry out widespread attacks on businesses and at least some federal agencies.
Attackers have exploited a vulnerability in the Sharepoint software and hit targets in various countries.
Microsoft SharePoint server hack likely caused by single actor — and thousands of firms now vulnerable: researchers
A global attack on Microsoft server software used by thousands of government agencies and businesses to share documents within organizations is likely the work of a single actor, a cybersecurity researcher said on Monday.
Giant Microsoft Hack Triggers ‘Mad Scramble’ Across the U.S.
Federal and state agencies have been plunged into panic after hackers prised open a gap in the armor of a Microsoft program’s security software, researchers have said. At least two unnamed federal agencies, as well as state legislatures, have reported problems with hacks targeting SharePoint servers, with Eye Security reportedly tracking breaches into European government servers. “There is definitely a mad scramble across the nation right now,” …
Coverage Details
Bias Distribution
- 62% of the sources are Center
To view factuality data please Upgrade to Premium