Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Anthropic CEO and Department of War Boss Pete Hegseth

    Pentagon Officially Labels Anthropic a Supply Chain Risk Over AI Limits in Military Operations

    Sam Altman Trump

    OpenAI Secures Department of War Deal for Hours After Anthropic Ban

    President Donald Trump Orders Federal Ban on Use of Anthropic AI Technology

    Facebook X (Twitter) Instagram
    Saturday, March 7
    Trending
    • Pentagon Officially Labels Anthropic a Supply Chain Risk Over AI Limits in Military Operations
    • OpenAI Secures Department of War Deal for Hours After Anthropic Ban
    • President Donald Trump Orders Federal Ban on Use of Anthropic AI Technology
    • Anthropic CEO Dario Amodei Rejects Department of War Demand to Drop AI Safeguards
    • Paramount-Skydance Wins Warner Bros. Acquisition Bid Against Netflix
    • Forbes 30 Under 30 CEOs Behind Bars: From Startup Darlings to Convicted Fraudsters
    • NASA Reveals Details of Medical Incident Behind Historic ISS Evacuation
    • Samsung Galaxy S26 Ultra: Everything You Need to Know
    LinkedIn Instagram X (Twitter) YouTube
    TechGenezTechGenez
    • AI
      Anthropic CEO and Department of War Boss Pete Hegseth

      Pentagon Officially Labels Anthropic a Supply Chain Risk Over AI Limits in Military Operations

      March 6, 2026
      Sam Altman Trump

      OpenAI Secures Department of War Deal for Hours After Anthropic Ban

      February 28, 2026

      President Donald Trump Orders Federal Ban on Use of Anthropic AI Technology

      February 28, 2026
      Anthropic CEO and Department of War Boss Pete Hegseth

      Anthropic CEO Dario Amodei Rejects Department of War Demand to Drop AI Safeguards

      February 27, 2026

      IBM Shares Plummet; $35 Billion Wiped Off Market Cap Due to Anthropic’s New AI

      February 24, 2026
    • Business
      1. Startups
      2. View All
      Forbes 30 under 30

      Forbes 30 Under 30 CEOs Behind Bars: From Startup Darlings to Convicted Fraudsters

      February 27, 2026

      StartupsExpo 2025: AI for Good – Driving Purposeful Innovation

      November 4, 2025
      Sam Altman, CEO of OpenAI. Kevin Dietsch/Getty Images

      OpenAI Sets Stage for $1 Trillion Blockbuster Public Stock Offering

      October 30, 2025
      Sam Altman, Sundar and Windsurf CEO

      Google’s $2.4B AI Talent Grab: Windsurf CEO Joins DeepMind After OpenAI Deal Collapses

      July 14, 2025
      Paramount-Skydance Wins Warner Bros. Acquisition Bid Against Netflix

      Paramount-Skydance Wins Warner Bros. Acquisition Bid Against Netflix

      February 27, 2026
      Forbes 30 under 30

      Forbes 30 Under 30 CEOs Behind Bars: From Startup Darlings to Convicted Fraudsters

      February 27, 2026
      Bitcoin Price Volatile

      Bitcoin Plunges Below $70,000, Wiping Out 44% of Peak Value

      February 23, 2026
      Elon Musk’s SpaceX

      SpaceX Lines Up Four Major Wall Street Banks Ahead of Blockbuster IPO

      January 22, 2026
    • Space
      SpaceX Crew 11

      NASA Reveals Details of Medical Incident Behind Historic ISS Evacuation

      February 27, 2026
      Elon Musk’s SpaceX

      SpaceX Lines Up Four Major Wall Street Banks Ahead of Blockbuster IPO

      January 22, 2026
      NASA Astronaut Suni Williams

      NASA Astronaut Suni Williams Retires After 27 Years and Record-Setting Career

      January 22, 2026
      SpaceX Crew 11

      SpaceX Crew-11 Astronauts Return to Earth in Historic Medical Evacuation from ISS

      January 15, 2026
      3I/ATLAS: The Third Interstellar Visitor – Comet or Alien Probe?

      3I/ATLAS: The Third Interstellar Visitor – Comet or Alien Probe?

      October 31, 2025
    • Cyber Security
      CEO of Under Armour is its founder, Kevin Plank,

      Under Armour Investigating Claims of Major Data Breach Affecting Millions of Customers

      January 22, 2026
      cyber security

      10 Proven Ways to Protect Yourself Online

      November 15, 2025

      65 Nations have Signed the United Nations Convention Against Cybercrime in Hanoi

      October 27, 2025

      Discord Confirms User Data Stolen in Third-Party Customer Service Breach

      October 8, 2025
      cyber attack caused delays at Brussels International Airport in Zaventem, Belgium, Saturday, Sept. 20, 2025. (AP Photo/Harry Nakos)

      UK Arrests Man in Ransomware Attack Disrupting Europe’s Busiest Airports

      September 25, 2025
    • Crypto
      Bitcoin Price Volatile

      Bitcoin Plunges Below $70,000, Wiping Out 44% of Peak Value

      February 23, 2026
      Coinbase Data Breach

      Coinbase Data Breach Exposes 69,000 Customers – What You Need to Know

      May 22, 2025
      Trump Establishes U.S. Strategic Bitcoin Reserve: A Bold Step or a Symbolic Gesture?

      Trump Establishes U.S. Strategic Bitcoin Reserve: A Bold Step or a Symbolic Gesture?

      March 7, 2025
      Trump Administration Unveils Bold Crypto Policy Overhaul

      Trump Administration Unveils Bold Crypto Policy Overhaul

      January 24, 2025
      Crypto's Star-Studded Turnaround: Inauguration Ball Celebrates Trump’s New Era of Digital Asset Policy

      Crypto’s Star-Studded Turnaround: Inauguration Ball Celebrates Trump’s New Era of Digital Asset Policy

      January 20, 2025
    • Auto
      The Tesla Diner

      Tesla Diner Opens in Hollywood: A Retro-Futuristic Hub for Dining and EV Charging

      July 22, 2025
      Elon Musk , Tesla CEO (c) CNN Money

      Tesla (TSLA) Stock Skyrockets on Robotaxi Launch in Austin, Texas

      June 23, 2025
      Tesla Cybertruck Trade-Ins

      Tesla Cybertruck Trade-Ins Are Here – And the Numbers Are Brutal

      May 27, 2025
      BYD and Tesla in Europe

      Tesla News: BYD Overtakes Tesla in European EV Sales

      May 22, 2025
      Mobius Motors

      Silver Box Acquires Kenya’s Mobius Motors After Failed Rescue Attempts

      March 14, 2025
    • More
      1. Gaming
      2. Telecom
      3. Social Media
      4. VR/AR
      5. Health
      6. User Data
      7. View All

      Discord Confidentially Files for IPO with Goldman Sachs and JPMorgan Chase

      January 7, 2026

      Discord Confirms User Data Stolen in Third-Party Customer Service Breach

      October 8, 2025
      Electronic Arts (EA)

      Electronic Arts (EA) Agrees to $55 Billion Buyout, Largest LBO in Gaming History

      September 29, 2025
      Fortnite Live Event ‘Super Showdown’

      Fortnite Live Event ‘Super Showdown’ Wows Players with Superman and Kraken Battle

      August 2, 2025
      Elon Musk and Nicolás Maduro

      Starlink Provides Free Internet Access in Venezuela After U.S. Airstrikes and Maduro Arrest

      January 5, 2026
      Elon Musk Starlink

      Starlink Global Outage Resolved: Cause Identified as Software Failure

      July 25, 2025
      Trump and Xi-Jinping Pic:: Getty Images

      US Moves to Ban Chinese Technology in Undersea Telecommunications Cables

      July 16, 2025
      United Wi-Fi by United Airlines

      United Airlines Takes Flight with Starlink: A New Era of In-Flight Internet Services

      January 6, 2025
      Meta Chief Executive Mark Zuckerberg at a congressional hearing. (Andrew Harnik / Associated Press)

      Meta CEO Mark Zuckerberg Testifies in LA Trial Over Youth Mental Health Claims

      February 18, 2026
      French President Emmanuel Macron

      France to Ban Under-15s from Social Media and Phones in High Schools from 2026

      January 2, 2026
      Photographer: Hollie Adams/Bloomberg

      Indonesia Suspends TikTok’s Operating License Over Data-Sharing Dispute

      October 4, 2025
      Whatsapp User Image_ Credit TechGenez

      WhatsApp Can Now Translate Messages on iOS and Android: Breaking Down Language Barriers

      September 25, 2025
      Meta's Mark Zuckerberg Unveils New AI Products: Smart Glasses, Chatbots, and More

      Meta’s Mark Zuckerberg Unveils New AI Products: Smart Glasses, Chatbots, and More

      September 27, 2023
      Ubisoft CEO Yves Guillemot

      Ubisoft Embraces the Potential of AI and VR for the Gaming Industry, says CEO

      June 19, 2023
      Sundai-Pichai-Google-ceo-techgenez

      Google CEO Sundar Pichai is excited about Apple’s Vision Pro Headset

      June 12, 2023
      Mark_Zuckerberg_wearing_Quest_3

      Mark Zuckerberg Criticizes Apple’s Vision Pro Headset

      June 10, 2023
      Open AI ChatGPT

      OpenAI Launches ChatGPT Health: A Dedicated AI Experience for Health and Wellness

      January 7, 2026
      The team watch on as Ricardo Hanel performs the procedure from Florida

      Dundee and US Surgeons Achieve World-First Remote Robotic Stroke Procedure Spanning 4,000 Miles

      November 11, 2025
      CEO of AstraZeneca Pascal Soriot

      AstraZeneca Strikes $555 Million Deal with Algen for Gene-Editing AI Technology

      October 7, 2025
      23andMe CEO Anne Wojcicki -Image Credit: Forbes

      Genetic Testing Pioneer 23andMe Files for Bankruptcy Protection

      March 26, 2025
      cyber security

      10 Proven Ways to Protect Yourself Online

      November 15, 2025

      Discord Confirms User Data Stolen in Third-Party Customer Service Breach

      October 8, 2025
      Congressman Andy Biggs - Getty Images

      US Lawmakers Condemn UK’s ‘Dangerous’ Demand for Access to Apple’s Encrypted Data

      February 16, 2025
      AT&T Customer Image (Mark Makela / Getty Images)

      Personal Information of 73 Million AT&T Customers Has Been Leaked on the Dark Web

      April 3, 2024
      Anthropic CEO and Department of War Boss Pete Hegseth

      Pentagon Officially Labels Anthropic a Supply Chain Risk Over AI Limits in Military Operations

      March 6, 2026
      Sam Altman Trump

      OpenAI Secures Department of War Deal for Hours After Anthropic Ban

      February 28, 2026

      President Donald Trump Orders Federal Ban on Use of Anthropic AI Technology

      February 28, 2026
      Anthropic CEO and Department of War Boss Pete Hegseth

      Anthropic CEO Dario Amodei Rejects Department of War Demand to Drop AI Safeguards

      February 27, 2026
    TechGenezTechGenez

    Microsoft Confirms a Massive Global Cyberattack Targeting its SharePoint Server Software

    July 21, 2025By Anane Ebenezer13,889 Views
    Satya Nadella Ceo of Microsoft - GettyImages
    Satya Nadella Ceo of Microsoft - GettyImages
    Share
    Facebook Twitter LinkedIn Copy Link

    REDMOND, July 21, 2025 – Microsoft has confirmed a massive global cyberattack targeting its SharePoint server software, a critical platform used by government agencies, businesses, and universities for document sharing and collaboration.

    The attack, exploiting a zero-day vulnerability tracked as CVE-2025-53770, has compromised at least 85 servers across 54 organizations, including U.S. federal and state agencies, energy companies, and European government entities.

    With no patch available for older SharePoint versions, tens of thousands of on-premises servers remain at risk, prompting urgent warnings from Microsoft, the FBI, and cybersecurity experts. The breach, dubbed “ToolShell,” highlights ongoing challenges in securing enterprise software amid escalating cyber threats.

    The Zero-Day Threat: CVE-2025-53770

    The attack exploits a critical vulnerability in on-premises SharePoint servers, identified as CVE-2025-53770, with a CVSS score of 9.8, indicating severe risk. This flaw allows unauthenticated attackers to execute remote code by deserializing untrusted data, enabling them to install malicious web shells and steal cryptographic keys.

    These keys, including ValidationKey and DecryptionKey, allow hackers to craft forged __VIEWSTATE payloads, granting persistent access even after patches are applied. The vulnerability is a variant of CVE-2025-49706, which Microsoft patched in its July 2025 Update Tuesday, but attackers quickly adapted, exploiting a new flaw to bypass the fix.

    Microsoft emphasized that SharePoint Online, part of Microsoft 365, is unaffected, as the vulnerability targets only on-premises servers. The attack, first identified by Dutch cybersecurity firm Eye Security on July 18, 2025, has been linked to malicious activities involving the upload of a file named “spinstall0.aspx” via PowerShell, which extracts critical server configurations. Eye Security reported that at least 54 organizations, including banks, universities, and government agencies, have been compromised, with the number likely higher due to undetected breaches.

    Scope and Impact of the Attack

    The breach has had a far-reaching impact, affecting a diverse range of organizations. According to The Washington Post, U.S. federal and state agencies, universities, energy companies, and an Asian telecommunications firm are among the victims. In one eastern U.S. state, attackers hijacked a public document repository, locking out officials and preventing access to critical government materials. Eye Security and Palo Alto Networks’ Unit 42 have tracked over 50 breaches, with some estimates suggesting tens of thousands of servers are vulnerable globally.

    The attack’s severity stems from its ability to bypass identity controls, including multi-factor authentication (MFA) and single sign-on (SSO), allowing attackers to gain privileged access. Once inside, hackers can exfiltrate sensitive data, deploy persistent backdoors, and move laterally across networks, potentially compromising connected services like Outlook, Teams, and OneDrive. Michael Sikorski, CTO of Unit 42 at Palo Alto Networks, warned, “If you have SharePoint on-prem exposed to the internet, you should assume that you have been compromised at this point.”

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-53770 to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply fixes by July 21, 2025. CISA, along with authorities in Canada and Australia, is actively investigating the breach, with the FBI coordinating with private-sector partners. The Center for Internet Security notified approximately 100 organizations, including public schools and universities, of potential vulnerabilities, though response efforts were hampered by a 65% cut in CISA’s threat-intelligence teams.

    Microsoft’s Response and Mitigation Efforts

    Microsoft issued an urgent alert on July 19, 2025, acknowledging the active exploitation of CVE-2025-53770 and a related spoofing flaw, CVE-2025-53771. On July 20, the company released emergency patches for SharePoint Subscription Edition and SharePoint 2019, with updates for SharePoint 2016 still in development.

    Customers are urged to apply these patches immediately and rotate ASP.NET machine keys to invalidate stolen cryptographic secrets. Microsoft also recommended enabling Antimalware Scan Interface (AMSI) integration, enabled by default in September 2023 updates for SharePoint 2016/2019 and Version 23H2 for Subscription Edition, and deploying Microsoft Defender for Endpoint to detect post-exploit activity.

    For organizations unable to apply patches or enable AMSI, Microsoft advises disconnecting SharePoint servers from the internet until updates are available. The company also provided indicators of compromise (IoCs), including monitoring for POST requests to “/_layouts/15/ToolPane.aspx” with a referer of “/_layouts/SignOut.aspx” and checking for the malicious file “spinstall0.aspx” (SHA256: 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514).

    Origins of the Vulnerability

    The attack leverages a vulnerability chain first demonstrated by Viettel Cyber Security at the Pwn2Own Berlin contest in May 2025, dubbed “ToolShell.” The original flaws, CVE-2025-49706 (authentication bypass) and CVE-2025-49704 (code injection), were patched in July, but public disclosure of exploit details by researchers, including CODE WHITE GmbH and Soroush Dalili, enabled attackers to develop a new exploit. Eye Security noted that the rapid weaponization of the zero-day followed these disclosures, highlighting the risks of sharing technical details before patches are widely applied.

    Industry and Public Reactions

    The cybersecurity community has reacted with alarm, with posts on X reflecting urgency and concern. @Osint613 reported breaches across U.S. agencies and energy companies, while @leviathan_news highlighted CISA’s warning about the attack’s global reach. @happygeek emphasized the lack of a patch for older versions, urging organizations to disconnect servers. Experts like Charles Carmakal of Mandiant Consulting stressed the need for immediate threat hunting, noting that patching alone is insufficient due to stolen cryptographic keys.

    Public sentiment on X, as seen in posts like @notreload_ai, underscores the attack’s potential for data theft and password harvesting, amplifying fears about its impact on critical infrastructure. The incident has also reignited criticism of Microsoft’s security practices, following previous breaches like the 2023 Chinese hack of federal email systems and a 2024 HealthEquity attack that exposed 4.3 million users’ data.

    Challenges and Controversies

    The attack poses several challenges:

    • Lack of a Comprehensive Patch: While patches for SharePoint Subscription Edition and 2019 are available, SharePoint 2016 remains vulnerable, leaving many organizations exposed.
    • Persistent Access: Stolen cryptographic keys allow attackers to maintain access even after patching, necessitating key rotation and extensive incident response.
    • Delayed Response: CISA’s reduced funding and staffing slowed notifications, with the Center for Internet Security taking six hours to warn 100 organizations.
    • Attribution Uncertainty: The attackers’ identity and motives remain unclear, with targets spanning the U.S., Europe, Asia, and China, complicating investigations.

    Critics argue that Microsoft’s reactive approach—patching one flaw only for attackers to exploit a variant—reflects a pattern of narrowly focused fixes. A 2024 U.S. government panel previously criticized Microsoft for security lapses, and this incident adds to concerns about its ability to secure widely used software.

    Future Outlook

    The SharePoint attack underscores the growing sophistication of cyber threats and the challenges of securing on-premises infrastructure. Organizations must prioritize immediate mitigation, including applying patches, enabling AMSI, and rotating machine keys, while also conducting threat hunting to detect compromises. The incident highlights the need for robust endpoint visibility and proactive cybersecurity measures, as SharePoint’s integration with services like Teams and Outlook amplifies the risk of network-wide breaches.

    Microsoft’s ongoing efforts to develop patches for older SharePoint versions and its coordination with CISA, the FBI, and global partners signal a commitment to addressing the crisis. However, the attack’s scale and the lack of immediate fixes for all versions underscore the urgency of modernizing legacy systems and adopting cloud-based solutions like SharePoint Online, which remain unaffected. As cyberattacks become a key tool in geopolitical and criminal strategies, this breach serves as a wake-up call for organizations to strengthen their defenses and for Microsoft to enhance its security development lifecycle.

    Conclusion

    The global SharePoint attack exploiting CVE-2025-53770 represents a critical cybersecurity crisis, compromising sensitive systems across governments, businesses, and universities. Microsoft’s emergency patches and mitigation guidance offer a path forward, but the absence of fixes for older versions and the persistence of stolen cryptographic keys pose ongoing risks.

    As investigations continue and organizations scramble to secure their servers, this incident highlights the fragility of on-premises infrastructure and the need for rapid, coordinated responses to zero-day threats. The tech world now watches closely to see how Microsoft and its customers navigate this escalating cyber storm.

    Related Posts

    Anthropic CEO and Department of War Boss Pete Hegseth
    Artificial Intelligence (AI) March 6, 2026

    Pentagon Officially Labels Anthropic a Supply Chain Risk Over AI Limits in Military Operations

    Sam Altman Trump
    Tech of the Day February 28, 2026

    OpenAI Secures Department of War Deal for Hours After Anthropic Ban

    Artificial Intelligence (AI) February 28, 2026

    President Donald Trump Orders Federal Ban on Use of Anthropic AI Technology

    Add A Comment
    Leave A Reply Cancel Reply

    Get in Touch
    • Contact Us
    • Advertise Here
    Listen to our Podcast
    TechGenez
    Facebook X (Twitter) Instagram YouTube LinkedIn
    • Advertising with TechGenez
    • Contact Us
    • About Us
    © 2026 All Rights Reserved || TechGenez Inc

    Type above and press Enter to search. Press Esc to cancel.

    Kindly Disable your AdBlocker!
    Kindly Disable your AdBlocker!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.