Latest Security News
Security Updates
Latest security news and articles covering recent vulnerabilities and their impacts.
New CrushFTP Critical Vulnerability Exploited in the Wild
2025-07-21 13:00
Infosecurity Magazine
1 CVE
CVE-2025-54309 could allow remote attackers to obtain admin access via HTTPS
Critical CrushFTP vulnerability exploited. Have you been targeted? (CVE-2025-54309)
2025-07-21 12:02
Help Net Security
1 CVE
Unknown attackers have exploited a vulnerability (CVE-2025‑54309) in the CrushFTP enterprise file-transfer server solution to gain administrative access to vulnerable deployments. It’s currently unclear what the attackers are using this access for, but data t…
GreenboneOS: CVE-2025-25257: Urgent Pre-Auth RCE in FortiWeb Fabric Connector
2025-07-21 11:21
Greenbone.net
1 CVE
A fresh vulnerability, CVE-2025-25257 (CVSS 9.6) in Fortinet’s FortiWeb Fabric Connector presents high risk globally. Although the CVE is still only in RESERVED status as of July 14th, 2025, it has already received a national CERT advisory from Belgium’s CERT…
Microsoft issues emergency patches for SharePoint zero-days exploited in “ToolShell” attacks
2025-07-21 11:14
Securityaffairs.com
2 CVEs
Microsoft patched an exploited SharePoint flaw (CVE-2025-53770) and disclosed a new one, warning of ongoing attacks on on-prem servers. Microsoft released emergency SharePoint updates for two zero-day flaws, tracked as CVE-2025-53770 and CVE-2025-53771, explo…
SharePoint zero-day CVE-2025-53770 actively exploited in the wild
2025-07-21 07:27
Securityaffairs.com
1 CVE
Microsoft warns of ongoing active exploitation of a SharePoint zero-day vulnerability, tracked as CVE-2025-53770. Microsoft warns of a SharePoint zero-day vulnerability, tracked as CVE-2025-53770 (CVSS score of 9.8), which is under active exploitation. Unfort…
Hackers actively exploiting unpatched Microsoft SharePoint vulnerability CVE-2025-53770
2025-07-21 04:44
Neowin
1 CVE
A new critical vulnerability, CVE-2025-53770 (ToolShell), is being actively exploited to attack unpatched on-premises Microsoft SharePoint Servers. Read more...
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks
2025-07-21 04:41
BleepingComputer
2 CVEs
Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in "ToolShell" attacks. [...]
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
2025-07-21 01:31
Biztoc.com
2 CVEs
Update 7/20/25: Added that there are actually two zero-days exploited and that Microsoft released a security update for SharePoint Subscription Edition. Critical zero-day vulnerabilities in Microsoft SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, h…
Active attacks target Microsoft SharePoint zero-day affecting on-premises servers
2025-07-20 22:41
SiliconANGLE News
1 CVE
A zero-day vulnerability in Microsoft Corp.’s SharePoint with no known patch is being exploited in the wild with security researchers warning that attackers are actively compromising servers across multiple sectors. The vulnerability, tracked as CVE-2025-5377…
Microsoft SharePoint servers under attack via zero-day vulnerability with no patch (CVE-2025-53770)
2025-07-20 21:01
Help Net Security
2 CVEs
Attackers are exploiting a zero-day variant (CVE-2025-53770) of a SharePoint remote code execution vulnerability (CVE-2025-49706) that Microsoft patched earlier this month, the company has confirmed on Saturday. CVE-2025-53770 is being leveraged to place a ba…
CVE-2025-53770: Frequently Asked Questions About Zero-Day SharePoint Vulnerability Exploitation
2025-07-20 20:45
Tenable.com
1 CVE
Successful exploitation of CVE-2025-53770 could expose MachineKey configuration details from a vulnerable SharePoint Server, ultimately enabling unauthenticated remote code execution.BackgroundTenable’s Research Special Operations (RSO) team has compiled this…
Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability (CVE-2025-53770) - CISA (.gov)
2025-07-20 19:54
Slashdot.org
1 CVE
Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability (CVE-2025-53770)CISA (.gov) Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Company ServersThe Hacker News SharePoint Under Attack: Microsoft Warns of Zero-Day Exp…
Critical Sharepoint 0-Day Vulnerablity Exploited CVE-2025-53770 (ToolShell), (Sun, Jul 20th)
2025-07-20 17:32
Sans.edu
1 CVE
Microsoft announced yesterday that a newly discovered critical remote code execution vulnerability in SharePoint is being exploited. There is no patch available. As a workaround, Microsoft suggests using Microsoft Defender to detect any attacks. To use Defend…
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
2025-07-20 15:40
BleepingComputer
1 CVE
A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, has been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. [...]
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog
2025-07-20 13:38
Securityaffairs.com
1 CVE
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiWeb flaw, tracked as CVE-2025-25257, …
Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability (CVE-2025-53770)
2025-07-20 12:00
Cisa.gov
1 CVE
CISA is aware of active exploitation of a new remote code execution (RCE) vulnerability enabling unauthorized access to on-premise SharePoint servers. While the scope and impact continue to be assessed, the new Common Vulnerabilities and Exposures (CVE), CVE-…
CISA Adds One Known Exploited Vulnerability, CVE-2025-53770 “ToolShell,” to Catalog
2025-07-20 12:00
Cisa.gov
1 CVE
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. See CISA’s Alert Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability (CVE-2025-53770) for more information and t…
UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities
2025-07-20 12:00
Cisa.gov
1 CVE
Update (07/22/2025): This Alert was updated to reflect newly released information from Microsoft, and to correct the actively exploited Common Vulnerabilities and Exposures (CVEs), which have been confirmed as CVE-2025-49706, a network spoofing vulnerability,…
Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Global Organizations
2025-07-20 09:52
Internet
2 CVEs
A critical security vulnerability in Microsoft SharePoint Server has been weaponized as part of an "active, large-scale" exploitation campaign. The zero-day flaw, tracked as CVE-2025-53770 (CVSS score: 9.8), has been described as a variant of CVE-2025-49706 (…
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWeb
2025-07-20 08:00
Help Net Security
1 CVE
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Update Google Chrome to fix actively exploited zero-day (CVE-2025-6558) For the fifth time this year, Google has patched a Chrome zero-day vulnerability (CVE-202…