Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Releases Final Patch For SharePoint Server Against ‘ToolShell’ Attacks

CRN by CRN
July 21, 2025
Home News
Share on FacebookShare on Twitter


The security update for SharePoint Server 2016 means that patches for ‘all supported versions of SharePoint’ are now available to protect against a pair of widely exploited vulnerabilities, the tech giant says.

Microsoft released the final remaining SharePoint Server patch Monday needed to protect against a pair of widely exploited vulnerabilities, which have fueled a global wave of cyberattacks against on-premises SharePoint customers in a campaign known as “ToolShell.”

The release of the security update for SharePoint Server 2016 means that patches for “all supported versions of SharePoint” affected by the flaws are now available, Microsoft said in an update Monday to its customer guidance advisory posted online.

[Related: China-Based Threat Actor Involved In Microsoft SharePoint Attacks: Mandiant CTO]

The ToolShell cyberattack campaign involves exploitation of on-premises Microsoft SharePoint Servers using a critical-severity remote code execution vulnerability (tracked at CVE-2025-53770) chained to a spoofing vulnerability (tracked at CVE-2025-53771). Researchers have estimated that at least several hundred organizations globally have been compromised so far, reportedly including U.S. government agencies, educational institutions and organizations that manage critical infrastructure.

On Sunday, Microsoft released emergency patches to address the vulnerabilities in the SharePoint Server Subscription Edition and SharePoint Server 2019, and said it was working on the remaining fixes for SharePoint Server 2016.

The final patch for was released shortly before 7 p.m., EDT, on Monday with the release of the security update for Microsoft SharePoint Enterprise Server 2016 (KB5002760), according to a post from the Microsoft Security Response Center on X.com. “Customers should apply these updates immediately to ensure they’re protected,” the post said.

The flaws do not impact SharePoint Online in Microsoft 365, Microsoft has said.

In its customer guidance advisory, Microsoft has also called it “critical” that customers rotate their SharePoint server keys, known as ASP.NET machine keys, in addition to patching.

“If you don’t rotate those keys, even if you patch the server, then that attacker still has access,” said Nick Hyatt, senior threat intelligence analyst at GuidePoint Security, in an interview with CRN Monday.

A researcher at cybersecurity vendor watchTowr, Ryan Dewhurst, said in an email to CRN Monday that the attacks have led to “widespread impact across hundreds of organizations—including those that many would consider ‘incredibly sensitive.’”

“We’re fairly certain it’s for once acceptable to call this a close-to-worst-case scenario,” said Dewhurst, head of proactive threat intelligence at watchTowr, in the email.

China-Based Actor Implicated

Charles Carmakal, CTO at Google Cloud-owned Mandiant Consulting, disclosed earlier Monday that while multiple threat actors have been involved in the compromises so far, indications of involvement originating from China have been observed.

“We assess that at least one of the actors responsible for this early exploitation is a China-nexus threat actor,” Carmakal said in a statement provided by email.

“It’s critical to understand that multiple actors are now actively exploiting this vulnerability,” he said in the statement. “We fully anticipate that this trend will continue, as various other threat actors, driven by diverse motivations, will leverage this exploit as well.”

In addition to nation-state attackers, security researchers suggested to CRN Monday that it’s likely that financially motivated threat actors are also seeking to exploit the critical SharePoint vulnerability.



Source link

Tags: CyberattacksCybersecurityMicrosoft SecurityServersVulnerabilities
CRN

CRN

Next Post
Leaked Memo: Anthropic CEO Says the Company Will Pursue Gulf State Investments After All

Leaked Memo: Anthropic CEO Says the Company Will Pursue Gulf State Investments After All

Recommended.

Electreon signs MoU to acquire InductEV’s assets, setting the stage for a global powerhouse in wireless EV charging future

Electreon signs MoU to acquire InductEV’s assets, setting the stage for a global powerhouse in wireless EV charging future

November 19, 2025
CaixaBank outlines artificial intelligence intentions in €5bn plan | Computer Weekly

CaixaBank outlines artificial intelligence intentions in €5bn plan | Computer Weekly

February 19, 2025

Trending.

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio