Navigation
Search
|
Microsoft Releases Emergency Patches for Actively Exploited SharePoint Zero-Days
Monday July 21, 2025. 05:23 PM , from Slashdot
![]() The vulnerabilities allow hackers to steal private digital keys from SharePoint servers without requiring credentials, enabling them to plant malware and access stored files and data. Eye Security, which first identified the attacks on Saturday, found dozens of actively exploited servers and warned that SharePoint's integration with Outlook, Teams, and OneDrive could enable further network compromise. Researcher Silas Cutler at cybersecurity firm Censys estimated more than 10,000 companies with SharePoint servers were at risk, with the largest concentrations in the United States, Netherlands, United Kingdom, and Canada. Microsoft released patches for SharePoint 2019 and Subscription Edition but is still working on fixes for SharePoint Server 2016. Administrators must install available updates immediately and rotate machine keys to prevent re-compromise, according to Microsoft's security guidance. Read more of this story at Slashdot.
https://it.slashdot.org/story/25/07/21/1523207/microsoft-releases-emergency-patches-for-actively-exp...
Related News |
25 sources
Current Date
Jul, Wed 23 - 23:50 CEST
|