ToolShell: a story of five vulnerabilities in Microsoft SharePointKaspersky Securelist·Jul 25, 07:00 UTC · Jul 25, 2025Vulnerability in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs160
Storm-2603 spotted deploying ransomware on exploited SharePoint serversHelp Net Security·Aug 4, 12:44 UTC · Aug 4, 2025Ransomware in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+2 CVEs160
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News·Jul 22, 03:59 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs60
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live AttacksThe Hacker News·Jul 23, 13:04 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
Microsoft pins on-prem SharePoint attacks on Chinese threat actorsHelp Net Security·Jul 24, 15:45 UTC · Jul 24, 2025Threat actor in the wildCVE-2025-49706CVE-2025-49704CVE-2025-53770+1 CVEs60
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
Chinese nation-state groups exploiting SharePoint vulnerability, Microsoft confirmsThe Record·Jul 22, 19:12 UTC · Jul 22, 2025Vulnerability in the wildCVE-2025-49706CVE-2025-49704CVE-2025-53770+1 CVEs60
Analyzing the vulnerability landscape in Q3 2025Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
ToolShell: Details of CVEs affecting SharePoint serversCisco Talos·Jul 23, 15:32 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
SharePoint vulnerability with 9.8 severity rating under exploit across globeArs Technica · Security·Jul 21, 19:30 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Microsoft issues emergency patches for SharePoint zeroSecurity Affairs·Jul 21, 17:26 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs160
Three hacking groups, two vulnerabilities and all eyes on ChinaThe Record·Dec 8, 15:09 UTC · Dec 8, 2025VulnerabilityCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
ToolShell Exploit: Critical SharePoint ZeroRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs160
Microsoft SharePoint attacks ensnare 400 victims, including federal agenciesCyberScoop·Jul 24, 18:39 UTC · Jul 24, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+3 CVEs60
U.S. CISA urges FCEB agencies to fix two Microsoft SharePoint flaws immediately and added them to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 23, 21:59 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-49704CVE-2025-49706CVE-2025-5377060
Microsoft SharePoint servers under attack via zero-day vulnerability (CVE-2025-53770)Help Net Security·Jul 22, 15:29 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs60
Microsoft fixes critical wormable Windows flaw (CVE-2025-47981)Help Net Security·Jul 22, 13:36 UTC · Jul 22, 2025Vulnerability in the wildCVE-2025-47981CVE-2025-49719CVE-2025-49717+2 CVEs160
Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber AttacksThe Hacker News·Jul 22, 07:16 UTC · Jul 22, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Microsoft Fix Targets Attacks on SharePoint Zero-DayKrebs on Security·Jul 21, 18:46 UTC · Jul 21, 2025Exploit / PoCCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs160
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacksCyberScoop·Feb 25, 13:30 UTC · Feb 25, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid responseCisco Talos·Oct 23, 10:00 UTC · Oct 23, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft's July PatchThe Hacker News·Oct 22, 12:56 UTC · Oct 22, 2025VulnerabilityCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs160
Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warningsCyberScoop·Aug 12, 20:21 UTC · Aug 12, 2025Vulnerability in the wildCVE-2025-53786CVE-2025-53770CVE-2025-53771+8 CVEs60
August 2025 Patch Tuesday forecast: Try, try againHelp Net Security·Aug 8, 00:00 UTC · Aug 8, 2025VulnerabilityCVE-2025-49704CVE-2025-49706CVE-2025-53770+3 CVEs60
Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware AttacksThe Hacker News·Aug 6, 14:41 UTC · Aug 6, 2025RansomwareCVE-2025-49706CVE-2025-4970460
⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and MoreThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Malware in the wildCVE-2025-49706CVE-2025-49704CVE-2025-20281+27 CVEs60
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched SystemsThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Ransomware in the wildCVE-2025-49706CVE-2025-4970460
What to know about ToolShell, the SharePoint threat under mass exploitationArs Technica · Security·Jul 23, 20:14 UTC · Jul 23, 2025Vulnerability in the wildCVE-2025-49706CVE-2025-4970460
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker GroupsThe Hacker News·Jul 22, 16:43 UTC · Jul 22, 2025RansomwareCVE-2025-49706CVE-2025-49704CVE-2025-53771+1 CVEs60
SharePoint under fire: new ToolShell attacks target enterprisesSecurity Affairs·Jul 22, 16:13 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-4970660
Microsoft SharePoint zero-day attacks pinned on ChinaCyberScoop·Jul 22, 15:54 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
U.S. CISA urges to immediately patch Microsoft SharePoint flaw adding it to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 21, 17:21 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
SharePoint zero-day CVE-2025Security Affairs·Jul 21, 07:27 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706CVE-2025-4970460
Microsoft Patch Tuesday for July 2025 — Snort rules and prominent vulnerabilitiesCisco Talos·Jul 10, 14:45 UTC · Jul 10, 2025Vulnerability in the wildCVE-2025-49735CVE-2025-49704CVE-2025-49695+11 CVEs60