{"id":5704,"date":"2025-07-29T05:04:10","date_gmt":"2025-07-29T05:04:10","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/29\/microsoft-sharepoint-zero-day-html\/"},"modified":"2025-07-29T05:04:10","modified_gmt":"2025-07-29T05:04:10","slug":"microsoft-sharepoint-zero-day-html","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/29\/microsoft-sharepoint-zero-day-html\/","title":{"rendered":"Microsoft SharePoint Zero-Day"},"content":{"rendered":"\n<div>Microsoft SharePoint Zero-Day<\/div>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to <a href=\"https:\/\/arstechnica.com\/security\/2025\/07\/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe\/\">steal data<\/a> worldwide:<\/p>\n<blockquote>\n<p>The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the vulnerability, which affects SharePoint Servers that infrastructure customers run in-house. Microsoft\u2019s cloud-hosted SharePoint Online and Microsoft 365 are not affected.<\/p>\n<\/blockquote>\n<p><a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/\">Here\u2019s<\/a> Microsoft on patching instructions. Patching isn\u2019t enough, as attackers have used the vulnerability to steal authentication credentials. It\u2019s an absolute mess. CISA has <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/20\/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities\">more information<\/a>. <a href=\"https:\/\/unit42.paloaltonetworks.com\/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770\/\">Also<\/a> <a href=\"https:\/\/www.akamai.com\/blog\/security-research\/sharepoint-vulnerability-rce-active-exploitation-detections-mitigations\">these<\/a> <a href=\"https:\/\/www.wired.com\/story\/microsoft-sharepoint-hack-china-end-of-life-updates\/\">four<\/a> <a href=\"https:\/\/thehackernews.com\/2025\/07\/hackers-exploit-sharepoint-zero-day.html\">links<\/a>. Two <a href=\"https:\/\/it.slashdot.org\/story\/25\/07\/21\/1523207\/microsoft-releases-emergency-patches-for-actively-exploited-sharepoint-zero-days\">Slashdot<\/a> <a href=\"https:\/\/news.slashdot.org\/story\/25\/07\/23\/1652240\/us-nuclear-weapons-agency-among-400-organizations-breached-by-chinese-hackers\">threads<\/a>.<\/p>\n<p>This is an unfolding security mess, and quite the hacking coup.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Bruce Schneier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/07\/microsoft-sharepoint-zero-day.html\">Go to bruce schneier<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft SharePoint Zero-Day Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to steal data worldwide: The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57,1264,97,158,1,416,517],"tags":[87],"class_list":["post-5704","post","type-post","status-publish","format-standard","hentry","category-bruce-schneier","category-exploits","category-hacking","category-microsoft","category-uncategorized","category-vulnerabilities","category-zero-day","tag-bruce-schneier"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5704"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5704"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5704\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5704"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5704"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5704"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}