{"id":8336,"date":"2025-07-20T11:56:09","date_gmt":"2025-07-20T11:56:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/8336\/"},"modified":"2025-07-20T11:56:09","modified_gmt":"2025-07-20T11:56:09","slug":"microsoft-confirms-ongoing-mass-sharepoint-attack-no-patch-available","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/8336\/","title":{"rendered":"Microsoft Confirms Ongoing Mass SharePoint Attack \u2014 No Patch Available"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/07\/1753012569_39_960x0.jpg\" alt=\"Microsoft SharePoint logo is seen displayed on a smartphone and Microsoft logo in the background. \" data-height=\"3141\" data-width=\"4188\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">Microsoft SharePoint is under attack.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Microsoft users are, once again, under attack. This time, the threat is not restricted to <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/07\/25-billion-email-users-urged-to-change-password---act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/07\/25-billion-email-users-urged-to-change-password---act-now\/\" target=\"_self\" aria-label=\"Outlook users\" rel=\"nofollow noopener\">Outlook users<\/a>, or involves a Windows <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/04\/new-windows-security-bypass-alert-for-chrome-and-edge-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/04\/new-windows-security-bypass-alert-for-chrome-and-edge-users\/\" target=\"_self\" aria-label=\"browser-based security bypass\" rel=\"nofollow noopener\">browser-based security bypass<\/a>, and unlike the recent Windows <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/17\/update-windows-now---microsoft-confirms-system-takeover-danger\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/17\/update-windows-now---microsoft-confirms-system-takeover-danger\/\" target=\"_self\" aria-label=\"authentication relay attack\" rel=\"nofollow noopener\">authentication relay attack<\/a> vulnerability, there is no patch, no magic update, to remedy this one. Which is bad news for Microsoft SharePoint Server users, as CVE-2025-53770 is currently under confirmed \u201cmass attack\u201d and on-premises servers across the world are being compromised. Here\u2019s what you need to know and do.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/20\/this-password-hack-jumps-from-laptop-to-smartphone---attacks-underway\/\" target=\"_blank\" aria-label=\"This Password Hack Jumps From Laptop To Smartphone \u2014 Attacks Underway\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/20\/this-password-hack-jumps-from-laptop-to-smartphone---attacks-underway\/\">ForbesThis Password Hack Jumps From Laptop To Smartphone \u2014 Attacks UnderwayBy Davey Winder<\/a><br \/>\nMicrosoft Confirms CVE-2025-53770 SharePoint Server Attacks<\/p>\n<p>It\u2019s been quite the few weeks for security warnings, what with Amazon informing 220 million customers of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/19\/amazon-warns-220-million-customers-of-prime-account-attacks\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/19\/amazon-warns-220-million-customers-of-prime-account-attacks\/\" target=\"_self\" aria-label=\"Prime account attacks\" rel=\"nofollow noopener\">Prime account attacks<\/a>, and claims of a mass <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/19\/amazon-ring-doorbell-may-28-mass-hacking-claim-goes-viral\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/19\/amazon-ring-doorbell-may-28-mass-hacking-claim-goes-viral\/\" target=\"_self\" aria-label=\"hack of Ring doorbells\" rel=\"nofollow noopener\">hack of Ring doorbells<\/a> going viral. The first of those can be mitigated by basic security hygiene, and the latter appears to be a false alarm. The same cannot be said for CVE-2025-53770, a newly uncovered and confirmed attack against users of SharePoint Server which is currently undergoing mass exploitation on a global level, according to the <a class=\"color-link\" href=\"https:\/\/research.eye.security\/sharepoint-under-siege\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/research.eye.security\/sharepoint-under-siege\/\" aria-label=\"Eye Research\">Eye Research<\/a> experts who discovered it. Microsoft, meanwhile, has <a class=\"color-link\" href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/\" aria-label=\"admitted\">admitted<\/a> that not only is it \u201caware of active attacks\u201d but, worryingly, \u201ca patch is currently not available for this vulnerability.\u201d<\/p>\n<p>CVE-2025-53770, which is also being called ToolShell, is a critical vulnerability in on-premises SharePoint. The end result of which is the ability for attackers to gain access and control of said servers without authentication. If that sounds bad, it\u2019s because it is. Very bad indeed.<\/p>\n<p>\u201cThe risk is not theoretical,\u201d the researchers warned, \u201cattackers can execute code remotely, bypassing identity protections such as MFA or SSO.\u201d Once they have, they can then \u201caccess all SharePoint content, system files, and configurations and move laterally across the Windows Domain.\u201d<\/p>\n<p>And then there\u2019s the theft of cryptographic keys. That can enable an attacker to \u201cimpersonate users or services,\u201d according to the report, \u201ceven after the server is patched.\u201d So, even when a patch is eventually released, and I would expect an emergency update to arrive fairly quickly for this one, the problem isn\u2019t solved. You will, it was explained, \u201cneed to rotate the secrets allowing all future tokens that can be created by the malicious actor to become invalid.\u201d<\/p>\n<p>And, of course, as SharePoint will often connect to other core services, including the likes of Outlook and Teams, oh and not forgetting OneDrive, the threat, if exploited, can and will lead to \u201cdata theft, password harvesting, and lateral movement across the network,\u201d the researchers warned.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/17\/web-browser-ai-hack-attacks-confirmed---what-you-need-to-know\/\" target=\"_blank\" aria-label=\"Web Browser AI Attacks Confirmed \u2014 What You Need To Know\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/17\/web-browser-ai-hack-attacks-confirmed---what-you-need-to-know\/\">ForbesWeb Browser AI Attacks Confirmed \u2014 What You Need To KnowBy Davey Winder<\/a><\/p>\n<p>Mitigating The Microsoft SharePoint Server Attacks<\/p>\n<p>While the Microsoft Security Response Center has stated that it is \u201cactively working to release a security update,\u201d and will \u201cprovide additional details as they are available,\u201d there is no patch at the time of writing. In the meantime, it advised that customers should apply the following mitigations:\u201d<\/p>\n<p>Configure Antimalware Scan Interface integration in SharePoint and deploy Defender AV on all SharePoint servers. \u201cIf you cannot enable AMSI,\u201d Microsoft said, \u201cwe recommend you consider disconnecting your server from the internet until a security update is available.\u201d<\/p>\n<p>I have approached Microsoft for a statement and will update this story with any further developments.<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft SharePoint is under attack. SOPA Images\/LightRocket via Getty Images Microsoft users are, once again, under attack. This&hellip;\n","protected":false},"author":2,"featured_media":8337,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,10261,10262,10260,10264,10256,10257,10258,10259,10263,105],"class_list":["post-8336","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-cve-2025-53770","tag-eye-research","tag-microsoft-confirms-sharepoint-attack","tag-microsoft-sharepoint-warning","tag-sharepoint","tag-sharepoint-attack","tag-sharepoint-hack","tag-sharepoint-hack-attack","tag-sharepoint-server-hack","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/8336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=8336"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/8336\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/8337"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=8336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=8336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=8336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}