Latest Security News
Security Updates
Latest security news and articles covering recent vulnerabilities and their impacts.
ChromeOS Multiple Vulnerabilities
2025-07-24 01:00
Hkcert.org
1 CVE
Multiple vulnerabilities were identified in ChromeOS. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and security restriction bypass on the targeted system. Note: CVE-2025-6558…
Imperva Customers Protected Against Critical “ToolShell” Zero‑Day in Microsoft SharePoint
2025-07-23 21:17
Imperva.com
1 CVE
A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, is under active exploitation in the wild. The vulnerability, with a CVSS score of 9.8, impacts on-premises SharePoint Server 2016, 2019, and Subscription Edition, and allows…
Sophos fixed two critical Sophos Firewall vulnerabilities
2025-07-23 20:23
Securityaffairs.com
3 CVEs
Sophos addressed five Sophos Firewall vulnerabilities that could allow remote attackers to execute arbitrary code. Sophos has fixed five vulnerabilities (CVE-2025-6704, CVE-2025-7624, CVE-2025-7382, CVE-2024-13974, CVE-2024-13973) in Sophos Firewall that coul…
Analyzing Sharepoint Exploits (CVE-2025-53770, CVE-2025-53771), (Wed, Jul 23rd)
2025-07-23 19:36
Sans.edu
2 CVEs
A few days after the exploit originally became widely known, there are now many different SharePoint exploit attempts in circulation. We do see some scans by researchers to identify vulnerable systems (or to scan for common artifacts of compromise), and a few…
Metasploit Module Released for Actively Exploited Microsoft SharePoint Flaw CVE-2025-53770
2025-07-23 15:32
SecurityOnline.info
1 CVE
The post Metasploit Module Released for Actively Exploited Microsoft SharePoint Flaw CVE-2025-53770 appeared first on Daily CyberSecurity.
Disrupting active exploitation of on-premises SharePoint vulnerabilities
2025-07-23 05:38
Biztoc.com
2 CVEs
On July 19, 2025, Microsoft Security Response Center (MSRC) published a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. The…
CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks
2025-07-23 04:40
Internet
2 CVEs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on July 22, 2025, added two Microsoft SharePoint flaws, CVE-2025-49704 and CVE-2025-49706, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. To tha…
Cisco confirms active exploitation of ISE and ISE-PIC flaws
2025-07-22 19:52
Securityaffairs.com
2 CVEs
Cisco warns of active exploits targeting Identity Services Engine (ISE) and ISE-PIC flaws, first observed in July 2025. Cisco confirmed attempted exploitation in the wild of recently disclosed ISE and ISE-PIC flaws (CVE-2025-20281, CVE-2025-20282, CVE-2025-20…
Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770
2025-07-22 16:30
Cloudflare.com
2 CVEs
Microsoft disclosed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, that are exploited to attack SharePoint servers. Possession of these cryptographic machine keys allows an attacker to forge authentication tokens and maintain access even if …
Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day
2025-07-22 16:14
Biztoc.com
1 CVE
Security researchers at Google and Microsoft say they have evidence that hackers backed by China are exploiting a zero-day bug in Microsoft SharePoint, as companies around the world scramble to patch the flaw. The bug, known officially as CVE-2025-53770 and d…
SharePoint under fire: new ToolShell attacks target enterprises
2025-07-22 16:12
Securityaffairs.com
1 CVE
While SentinelOne did not attribute the attack to a specific threat actor, The Washington Post linked it to China-nexus acors. On July 19, Microsoft confirmed active exploitation of a zero-day vulnerability, tracked as CVE-2025-53770 in on-prem SharePoint Ser…
Hackers Exploit Microsoft SharePoint Flaws in Global Breaches
2025-07-22 13:08
HackRead
1 CVE
Hackers are exploiting critical SharePoint flaws (CVE-2025-53770/53771) to breach global targets, including governments and corporations. Microsoft urges immediate action. Learn about the active attacks and how to protect your network from credential theft an…
CISA Adds Four Known Exploited Vulnerabilities to Catalog
2025-07-22 12:00
Cisa.gov
2 CVEs
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-54309 CrushFTP Unprotected Alternate Channel Vulnerability CVE-2025-6558 Google Chromium ANGLE a…
CISA Adds Two Known Exploited Vulnerabilities to Catalog
2025-07-22 12:00
Cisa.gov
2 CVEs
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability CVE-2025-49706 Microsoft SharePoint Impro…
CrushFTP zero-day actively exploited at least since July 18
2025-07-22 10:31
Securityaffairs.com
1 CVE
Hackers exploit CrushFTP zero-day, tracked as CVE-2025-54309, to gain admin access via HTTPS when DMZ proxy is off. Threat actors are exploiting a zero-day vulnerability, tracked as CVE-2025-54309 (CVSS score of 9.0), in the managed file transfer software Cru…
CVE-2025-53770: Zero-Day Exploit Impacts Microsoft SharePoint Services
2025-07-21 23:14
Zscaler.com
1 CVE
IntroductionOn July 19, 2025, Microsoft published an advisory for CVE-2025-53770, a critical zero-day vulnerability that allows unauthenticated attackers to execute arbitrary code impacting on-premises SharePoint servers. The vulnerability, dubbed ToolShell, …
Proactive Security and Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771)
2025-07-21 23:08
Trendmicro.com
2 CVEs
CVE-2025-53770 and CVE-2025-53771 are vulnerabilities in on-premise Microsoft SharePoint Servers that evolved from previously patched flaws, allowing unauthenticated remote code execution through advanced deserialization and ViewState abuse.
ToolShell: Details of CVEs Affecting SharePoint Servers
2025-07-21 20:33
Talosintelligence.com
2 CVEs
Cisco Talos is aware of the ongoing exploitation of CVE-2025-53770 and CVE-2025-53771 in the wild. These are path traversal vulnerabilities affecting SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Server 2019.
Microsoft Releases Emergency Patches for Actively Exploited SharePoint Zero-Days
2025-07-21 15:23
Slashdot.org
2 CVEs
Microsoft has released emergency security updates for two actively exploited zero-day vulnerabilities in SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, that have compromised servers worldwide in what researchers call "ToolShell" attacks. The U.S. C…
菴処
2025-07-21 15:00
Ryukoku.ac.jp
4 CVEs
2025 綛7 禹礇絅磧彜羂 (2025.07.10) d信罩c Sharepoint CVE-2025-49704 CVE-2025-49706 Pwn2Own ㏍сToolShell 違ToolShell 荐眼 CVE-2025-53770 CVE-2025-53771 違 Sharepoint (⒢ケ 紙с Customer guidance for SharePoint vulnerability CVE-2025-53770 (Microsoft, 2025.07.19…