Critical SharePoint Zero-Day Exploited in 75+ Organizations

1 min read
Source: The Hacker News
Critical SharePoint Zero-Day Exploited in 75+ Organizations
Photo: The Hacker News
TL;DR Summary

A critical zero-day vulnerability in Microsoft SharePoint Server, CVE-2025-53770, is actively being exploited in large-scale attacks, breaching over 75 organizations worldwide. Microsoft is working on a fix, but until then, recommended mitigations include enabling AMSI integration and deploying Defender AV. The attack chain involves delivering ASPX payloads via PowerShell to steal server keys, enabling remote code execution and persistent access.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

88%

52060 words

Want the full story? Read the original article

Read on The Hacker News