{"id":13102,"date":"2025-07-22T02:00:15","date_gmt":"2025-07-22T02:00:15","guid":{"rendered":"https:\/\/hostnoc-revamp.branex.org\/blog\/?p=13102"},"modified":"2025-07-21T11:55:44","modified_gmt":"2025-07-21T11:55:44","slug":"microsoft-warns-governments-and-businesses","status":"publish","type":"post","link":"https:\/\/hostnoc-revamp.branex.org\/blog\/microsoft-warns-governments-and-businesses\/","title":{"rendered":"Microsoft Warns Governments and Businesses of Active \u201cZero\u2011Day\u201d Attacks Targeting SharePoint Servers"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Microsoft warns governments and businesses of active \u201c<strong>Zero\u2011Day<\/strong>\u201d attacks targeting SharePoint servers exploiting a critical <a href=\"https:\/\/hostnoc-revamp.branex.org\/blog\/zero-day-exploits\/\">zero\u2011day vulnerability<\/a> in its SharePoint Server software, impacting government agencies, private enterprises, and educational institutions worldwide. The announcement, made in a security alert on July 19\u201320, underscores an escalating cyber\u2011espionage campaign targeting on\u2011premises deployments while leaving cloud\u2011based SharePoint Online unaffected .<\/span><\/p>\n<p>Microsoft warns governments and businesses about active zero day attacks. Here are key details.<\/p>\n<h2>Microsoft Warns Governments and Businesses of Active \u201cZero\u2011Day\u201d Attacks Targeting SharePoint Servers<\/h2>\n<p>Microsoft warns governments and Businesses of active zero day attacks targeting SharePoint servers. Interested in learning more? Read on to find out more.<\/p>\n<h3><b>Scope of the Attack &amp; Affected Targets<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Unnamed threat actors have leveraged a hitherto undisclosed vulnerability to launch a series of remote code execution exploits via a \u201c<strong>ToolShell<\/strong>\u201d attack chain. This zero\u2011day vulnerability, now tracked as CVE\u20112025\u201153770 (and in some cases CVE\u20112025\u201153771 by follow\u2011on patches), allows unauthenticated attackers to bypass normal security controls, upload web shells, move laterally within networks, and extract sensitive cryptographic material such as machine\u2011key configurations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Private researchers\u2014including <a href=\"https:\/\/hostnoc-revamp.branex.org\/blog\/google-io-2025\/\">Google<\/a> Threat Intelligence, Eye Security, and <a href=\"https:\/\/unit42.paloaltonetworks.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Palo Alto Networks&#8217; Unit 42<\/a>\u2014have detected dozens of severely compromised servers and reported a large\u2011scale exploitation effort that began around July 18\u201319.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Impacted systems span multiple sectors, including U.S. federal and state agencies, universities, energy infrastructure companies, and a major Asian telecommunications provider. While the exact number of compromised servers remains unclear, analysts estimate that tens of thousands of SharePoint Server instances are at risk.<\/span><\/p>\n<h3><b>Nature and Severity of the Vulnerability<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The exploit chain combines two critical flaws: CVE\u20112025\u201149706 (spoofing vulnerability) and CVE\u20112025\u201149704 (remote code execution). Attackers leveraged these to establish a foothold and escalate privileges without authentication. The newly assigned CVE\u20112025\u201153770 is essentially a variant or chained iteration of these earlier bugs. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added the vulnerability to its Known\u202fExploited Vulnerabilities catalog, emphasizing its urgency.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">CrowdStrike\u2019s Adam Meyers warned: \u201c<strong>Anybody who\u2019s got a hosted SharePoint server has got a problem<\/strong>\u201d. With a CVSS score of 9.8 &#8212; on the threshold of \u201c<\/span><b>critical<\/b><span style=\"font-weight: 400;\">\u201d\u2014the exploit enables full server takeover, persistent access via web shells, and exfiltration of sensitive data.<\/span><\/p>\n<h3><b>Microsoft Warns Governments and Businesses of Active \u201cZero\u2011Day\u201d Attacks : Response and Remediation Steps<\/b><\/h3>\n<p>Microsoft warns governments and businesses <span style=\"font-weight: 400;\">of active exploits and stated that they are coordinating closely with CISA, the Department of Defense Cyber Defense Command, FBI, and other global cybersecurity partners. In its advisory, the company emphasized that only on\u2011premises SharePoint Server installations (2016, 2019, and Subscription Edition) are affected; SharePoint Online (part of Microsoft 365) remains secure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As of July 20\u201321, Microsoft released <a href=\"https:\/\/www.bleepingcomputer.com\/news\/microsoft\/microsoft-releases-emergency-patches-for-sharepoint-rce-flaws-exploited-in-attacks\/\" target=\"_blank\" rel=\"nofollow noopener\">emergency patches<\/a> for Subscription Edition and SharePoint 2019 (via KB5002768 and KB5002754), with updates for SharePoint 2016 still pending.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Their recommendation for now:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Immediate <a href=\"https:\/\/hostnoc-revamp.branex.org\/blog\/patching-tips-from-experts\/\">patching<\/a><\/b><span style=\"font-weight: 400;\"> \u2013 subscription and 2019 editions prioritized.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Enable AMSI<\/b><span style=\"font-weight: 400;\"> integration and deploy Defender Antivirus to block unauthorized payloads.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Deploy Defender for Endpoint<\/b><span style=\"font-weight: 400;\"> or equivalent endpoint detection tools to identify post\u2011exploit activity.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Disconnect vulnerable servers<\/b><span style=\"font-weight: 400;\"> from the internet if mitigation tools cannot be activated.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Rotate machine\u2011key configurations<\/b><span style=\"font-weight: 400;\"> and restart IIS to invalidate any stolen credentials.<\/span><\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\"><a href=\"https:\/\/hostnoc-revamp.branex.org\/blog\/microsoft-build-2025\/\">Microsoft<\/a> emphasized that long-term protection involves applying these security updates and regularly performing threat-hunting activities to detect and eradicate any persistent backdoors.<\/span><\/p>\n<h3>Microsoft Warns Governments and Businesses of Active \u201cZero\u2011Day\u201d Attacks: Implications and Reactions<\/h3>\n<p><span style=\"font-weight: 400;\">Security Week notes that Google\u2019s intelligence team observed attackers installing web shells and exfiltrating cryptographic keys, enabling silent, persistent server control. Experts warn the ToolShell exploit is especially insidious because it blends into normal SharePoint traffic, complicating detection.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This incident echoes Microsoft\u2019s 2021 Exchange Server breach\u2014another zero\u2011day compromise that affected hundreds of thousands of servers and exposed deep supply\u2011chain vulnerabilities. Those attacks highlighted persistent challenges in defending on\u2011premises software in an increasingly hostile cyber landscape.<\/span><\/p>\n<h3><b>Final Word for Administrators<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Organizations operating on\u2011premises SharePoint servers must act without delay:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Deploy Microsoft\u2019s July 2025 security updates immediately.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Enable AMSI and use endpoint protection tools.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Segregate vulnerable servers from public\u2011facing networks until fully secured.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Investigate any signs of compromise\u2014including suspicious .aspx files or web\u2011shell indicators\u2014and rotate machine keys.<\/span><span style=\"font-weight: 400;\">\n<p><\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Remain vigilant for secondary CVE\u20112025\u201153771 patches, especially for 2016 systems.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">With tens of thousands of vulnerable servers still exposed and skilled adversaries actively exploiting them, the imperative for swift response cannot be overstated. For now, Microsoft\u2019s emergency patches and hardening guidelines are the frontline defense\u2014provided they are deployed in time.<\/span><\/p>\n<p>Microsoft warns governments and businesses of active \u201c<strong>Zero\u2011Day<\/strong>\u201d attacks. What steps are you taking to protect your business from these attacks? Share it with us in the comments section below.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft warns governments and businesses of active \u201cZero\u2011Day\u201d attacks targeting SharePoint servers exploiting a critical zero\u2011day vulnerability in its SharePoint Server software, impacting government agencies, private<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":3,"featured_media":13103,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[43],"tags":[],"class_list":["post-13102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts\/13102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/comments?post=13102"}],"version-history":[{"count":1,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts\/13102\/revisions"}],"predecessor-version":[{"id":13104,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts\/13102\/revisions\/13104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/media\/13103"}],"wp:attachment":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/media?parent=13102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/categories?post=13102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/tags?post=13102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}