Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SharePoint Under Attack: Microsoft Warns of Zero-Day Exploited in the Wild – No Patch Available

SharePoint Under Attack: Microsoft Warns of Zero-Day Exploited in the Wild – No Patch Available

Posted on July 20, 2025July 20, 2025 By CWS

Microsoft issued an pressing warning on Saturday to SharePoint Server clients, saying lively assaults are concentrating on a zero-day vulnerability within the software program product, which has been assigned CVE-2025-53770 with a CVSS rating of 9.8.

A patch is presently not accessible for the flaw, which Microsoft says is a variant of CVE-2025-49706.

The Redmond, Washington-based tech large stated a safety replace is presently within the works and supplied mitigation directions and detection steering. Safety groups ought to take fast motion to implement mitigations within the meantime.

“Google Menace Intelligence Group has noticed risk actors exploiting this vulnerability to put in webshells and exfiltrate cryptographic secrets and techniques from sufferer servers,” a Google Spokesperson instructed SecurityWeek. “This enables for persistent, unauthenticated entry and presents a major threat to affected organizations.”

Researchers at Eye Safety say they found “dozens of techniques actively compromised,” which they are saying probably occurred in assaults round of July 18th round 18:00 CET and July nineteenth round 07:30 CET.

“To guard your on-premises SharePoint Server setting, we advocate clients configure AMSI integration in SharePoint and deploy Defender AV on all SharePoint servers. It will cease unauthenticated attackers from exploiting this vulnerability,” Microsoft defined it its advisory.

“Organizations have to implement mitigations instantly (and the patch when accessible), assume compromise, examine whether or not the system was compromised previous to the patch/mitigation, and take remediation actions,” commented Charles Carmakal, CTO, Mandiant Consulting – Google Cloud.

Microsoft stated it might present updates and extra steering as they turn out to be accessible.Commercial. Scroll to proceed studying.

Useful Hyperlinks and assets for CVE-2025-53770:

SecurityWeek will replace this text and supply further protection as particulars developed.

Security Week News Tags:Attack, Exploited, Microsoft, Patch, SharePoint, Warns, Wild, ZeroDay

Post navigation

Previous Post: Critical Unpatched SharePoint Zero-Day Actively Exploited, Breaches 75+ Global Organizations
Next Post: EncryptHub Targets Web3 Developers Using Fake AI Platforms to Deploy Fickle Stealer Malware

Related Posts

The Y2K38 Bug Is a Vulnerability, Not Just a Date Problem, Researchers Warn The Y2K38 Bug Is a Vulnerability, Not Just a Date Problem, Researchers Warn Security Week News
Equixly Raises  Million for AI-Powered API Penetration Testing Equixly Raises $11 Million for AI-Powered API Penetration Testing Security Week News
Check Point Boosts AI Security with New Acquisitions Check Point Boosts AI Security with New Acquisitions Security Week News
Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Critical Vulnerability Puts 60,000 Redis Servers at Risk of Exploitation Security Week News
Astelia Secures M to Enhance Cybersecurity Solutions Astelia Secures $35M to Enhance Cybersecurity Solutions Security Week News
Stryker Hit by Major Cyberattack Linked to Iran Stryker Hit by Major Cyberattack Linked to Iran Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark