ToolShell: a story of five vulnerabilities in Microsoft SharePointKaspersky Securelist·Jul 25, 07:00 UTC · Jul 25, 2025Vulnerability in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live AttacksThe Hacker News·Jul 23, 13:04 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber AttacksThe Hacker News·Jul 22, 07:16 UTC · Jul 22, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
ToolShell Exploit: Critical SharePoint ZeroRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
Microsoft SharePoint attacks ensnare 400 victims, including federal agenciesCyberScoop·Jul 24, 18:39 UTC · Jul 24, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+3 CVEs60
Microsoft pins on-prem SharePoint attacks on Chinese threat actorsHelp Net Security·Jul 24, 15:45 UTC · Jul 24, 2025Threat actor in the wildCVE-2025-49706CVE-2025-49704CVE-2025-53770+1 CVEs60
ToolShell: Details of CVEs affecting SharePoint serversCisco Talos·Jul 23, 15:32 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Microsoft SharePoint servers under attack via zero-day vulnerability (CVE-2025-53770)Help Net Security·Jul 22, 15:29 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs60
Microsoft issues emergency patches for SharePoint zeroSecurity Affairs·Jul 21, 17:26 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs160
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Analyzing the vulnerability landscape in Q3 2025Kaspersky Securelist·Dec 3, 10:00 UTC · Dec 3, 2025VulnerabilityCVE-2018-0802CVE-2017-11882CVE-2017-0199+6 CVEs60
Storm-2603 spotted deploying ransomware on exploited SharePoint serversHelp Net Security·Aug 4, 12:44 UTC · Aug 4, 2025Ransomware in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+2 CVEs60
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News·Jul 22, 03:59 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-49704CVE-2025-49706+1 CVEs60
SharePoint vulnerability with 9.8 severity rating under exploit across globeArs Technica · Security·Jul 21, 19:30 UTC · Jul 21, 2025Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Microsoft Fix Targets Attacks on SharePoint Zero-DayKrebs on Security·Jul 21, 18:46 UTC · Jul 21, 2025Exploit / PoCCVE-2025-53770CVE-2025-49706CVE-2025-49704+1 CVEs60
Microsoft: Attackers Actively Compromising OnInfosecurity Magazine·Jul 21, 11:00 UTC · Jul 21, 2025Exploit / PoCCVE-2025-53770CVE-2025-5377160
Attackers are handing off access in 22 seconds, Mandiant findsHelp Net Security·Jun 19, 12:06 UTC · Jun 19, 2026RansomwareCVE-2025-31324CVE-2025-61882CVE-2025-53770+1 CVEs60
Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacksCyberScoop·Feb 25, 13:30 UTC · Feb 25, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
Threat AdvisoryCisco Talos·Dec 19, 16:50 UTC · Dec 19, 2025Advisory in the wildCVE-2026-20182CVE-2025-20333CVE-2025-20362+6 CVEs160
Three hacking groups, two vulnerabilities and all eyes on ChinaThe Record·Dec 8, 15:09 UTC · Dec 8, 2025VulnerabilityCVE-2025-49704CVE-2025-49706CVE-2025-53770+1 CVEs60
Threat Actors Ramp Up Public App Exploits as ToolShell Gains TractionInfosecurity Magazine·Oct 24, 12:29 UTC · Oct 24, 2025Threat actor in the wildCVE-2025-53770CVE-2025-5377160
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid responseCisco Talos·Oct 23, 10:00 UTC · Oct 23, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs60
Microsoft fixes "BadSuccessor" Kerberos vulnerability (CVE-2025-53779)Help Net Security·Aug 29, 08:47 UTC · Aug 29, 2025Vulnerability in the wildCVE-2025-53779CVE-2025-53770CVE-2025-53771+6 CVEs160
Microsoft Patch Tuesday follows SharePoint attacks, Exchange server warningsCyberScoop·Aug 12, 20:21 UTC · Aug 12, 2025Vulnerability in the wildCVE-2025-53786CVE-2025-53770CVE-2025-53771+8 CVEs60
August 2025 Patch Tuesday forecast: Try, try againHelp Net Security·Aug 8, 00:00 UTC · Aug 8, 2025VulnerabilityCVE-2025-49704CVE-2025-49706CVE-2025-53770+3 CVEs60
Ransomware Deployed in Compromised SharePoint ServersInfosecurity Magazine·Jul 24, 14:45 UTC · Jul 24, 2025RansomwareCVE-2025-53770CVE-2025-5377160
Chinese nation-state groups exploiting SharePoint vulnerability, Microsoft confirmsThe Record·Jul 22, 19:12 UTC · Jul 22, 2025Vulnerability in the wildCVE-2025-49706CVE-2025-49704CVE-2025-53770+1 CVEs60
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker GroupsThe Hacker News·Jul 22, 16:43 UTC · Jul 22, 2025RansomwareCVE-2025-49706CVE-2025-49704CVE-2025-53771+1 CVEs60
Microsoft SharePoint zero-day attacks pinned on ChinaCyberScoop·Jul 22, 15:54 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
SharePoint ‘ToolShell’ Vulnerabilities Exploited by Chinese HackersInfosecurity Magazine·Jul 22, 15:40 UTC · Jul 22, 2025VulnerabilityCVE-2025-53770CVE-2025-5377160
U.S. CISA urges to immediately patch Microsoft SharePoint flaw adding it to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 21, 17:21 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49706+1 CVEs60
Warnings issued as hackers actively exploit critical zeroThe Record·Jul 21, 11:00 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-53770CVE-2025-5377160