CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live AttacksThe Hacker News·Jul 23, 13:04 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
ToolShell Exploit: Critical SharePoint ZeroRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs160
ToolShell: Details of CVEs affecting SharePoint serversCisco Talos·Jul 23, 15:32 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Microsoft SharePoint servers under attack via zero-day vulnerability (CVE-2025-53770)Help Net Security·Jul 22, 15:29 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs60
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News·Jul 22, 03:59 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs60
Microsoft Fix Targets Attacks on SharePoint Zero-DayKrebs on Security·Jul 21, 18:46 UTC · Jul 21, 2025Exploit / PoCCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs160
Microsoft: Attackers Actively Compromising OnInfosecurity Magazine·Jul 21, 11:00 UTC · Jul 21, 2025Exploit / PoCCVE-2025-53770CVE-2025-5377160
Microsoft SharePoint zero-day attacks pinned on ChinaCyberScoop·Jul 22, 15:54 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
U.S. CISA urges to immediately patch Microsoft SharePoint flaw adding it to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 21, 17:21 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
Warnings issued as hackers actively exploit critical zeroThe Record·Jul 21, 11:00 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-5377160