Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Unpatched SharePoint Servers Targeted by Hackers

Unpatched SharePoint Servers Targeted by Hackers

Posted on June 24, 2026 By CWS

Unpatched on-premises SharePoint servers have emerged as a significant target for advanced cyber actors exploiting known vulnerabilities to install ransomware and establish covert access points.

Prolonged Network Breaches

These cyber intrusions are not mere opportunistic attacks. They involve strategic, multi-phase operations designed to maintain a presence within a network without detection. The primary group orchestrating these attacks, identified as Storm-2603, has been focusing on vulnerable SharePoint servers since mid-2025.

Storm-2603 leverages publicly disclosed vulnerabilities, notably CVE-2025-49706 and CVE-2025-49704, to gain initial access. Additionally, evidence of attempts to exploit CVE-2025-11371, a flaw allowing unauthorized local file access, has been uncovered.

Complexity of the Attacks

Microsoft’s Detection and Response Team (DART) conducted a thorough investigation, revealing the intricacy of these attacks, which surpassed typical ransomware activities. Surprisingly, two different threat actors operated simultaneously within the same network, obscuring each other’s activities.

Investigators were able to trace the full attack sequence only by correlating data across various identities, endpoints, and cloud activities. This incident, part of Microsoft’s Cyberattack Series No. 9, underlined how ransomware is often just a visible part of a more complex breach.

Defensive Measures and Response

The attackers, once inside, swiftly set up for a prolonged stay. They utilized Velociraptor, a legitimate forensic tool, to map the environment and establish remote access channels via Cloudflare tunnels, Zoho Assist, and Visual Studio Code.

To maintain network control, they created new administrative accounts and deployed a vulnerable driver, NSecKrnl.sys, for deep kernel-level access. This technique, known as Bring Your Own Vulnerable Driver (BYOVD), enables disabling security tools without detection.

A second unknown actor, using different methods, extracted Active Directory credentials by crafting an NTDS.zip archive and moving laterally using WinRM, a Windows remote management tool.

Microsoft’s Response and Recommendations

Microsoft’s DART swiftly initiated daily updates with the affected entity, highlighting risks and coordinating containment strategies. By integrating data from diverse security platforms, they identified both intrusion streams to prevent further damage.

Organizations are urged to prioritize patching, especially for SharePoint servers, and to strengthen defenses by securing high-privilege accounts, enforcing identity controls, and monitoring for abnormal sign-in activities. Comprehensive endpoint protection and regular audits of remote access tools are essential, alongside developing and testing incident response plans proactively.

Follow us on Google News, LinkedIn, and X for more updates, and consider setting CSN as a preferred source in Google.

Cyber Security News Tags:BYOVD, cyber threat, Cybersecurity, data exfiltration, endpoint protection, Malware, Microsoft DART, network security, ransomware attacks, remote access, SharePoint security, Storm-2603, Vulnerability

Post navigation

Previous Post: Mistic RAT Expands Ransomware Threat Landscape
Next Post: Rise of AI-Powered Cyber Threats Shifts Security Landscape

Related Posts

New “123 | Stealer” Advertised on Underground Hacking Forums for 0 Per Month New “123 | Stealer” Advertised on Underground Hacking Forums for $120 Per Month Cyber Security News
28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild 28,000+ Citrix Servers Exposed to Active 0-Day RCE Vulnerability Exploited in the Wild Cyber Security News
ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices Cyber Security News
APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities APT36 Hackers Used Python-Based ELF Malware to Target Indian Government Entities Cyber Security News
New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins New Windows-Based Airstalk Malware Employs Multi-Threaded C2 Communication to Steal Logins Cyber Security News
Apple Resolves iPhone Privacy Flaw Affecting Signal Apple Resolves iPhone Privacy Flaw Affecting Signal Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns
  • CSS Vulnerabilities Threaten Webmail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark