Close Menu
  • Startup News
  • Startup Stories
  • Sector Watch
  • Founders Desk
  • Top 10
  • Funding & Deals
  • India Insider

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Goldman Sachs Sells ₹355 Cr in Eternal Shares in Block Deal

October 4, 2025

Lenskart Gets SEBI Approval for ₹2,150 Cr IPO

October 4, 2025

BVG India’s IPO: ₹300 Cr Fresh Capital + Share Sale to Scale Business

October 3, 2025
Facebook X (Twitter) Instagram
startupstoryindia.comstartupstoryindia.com
Facebook Instagram YouTube LinkedIn
SUBSCRIBE
  • Startup News
  • Startup Stories
  • Sector Watch
  • Founders Desk
  • Top 10
  • Funding & Deals
  • India Insider
startupstoryindia.comstartupstoryindia.com
Home»Startup News»Critical Zero-Day in Microsoft SharePoint Under Active Attack Patch Immediately
Startup News

Critical Zero-Day in Microsoft SharePoint Under Active Attack Patch Immediately

Aman AtulyaBy Aman AtulyaJuly 22, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

A severe zero-day vulnerability in Microsoft’s on-premises SharePoint Server (CVE-2025-53770, dubbed “ToolShell”) is being actively exploited worldwide. Early breaches show attackers with full remote code execution, persistent access, and cryptographic key theft—raising alarms for governments, enterprises, and critical institutions.

Why It’s Dangerous

  • Attackers can infiltrate SharePoint servers via unauthenticated remote code execution, insert malware, and steal or manipulate data.
  • Tools like Eye Security and Palo Alto Unit 42 warn that once attackers deploy web shells, detection is tough often leading to lateral movement across connected systems.
  • Over 8,000 servers, spanning energy firms, banks, universities, and government agencies, have been identified as vulnerable.

Microsoft & Agencies Sound the Alarm

  • Microsoft has issued emergency patches for SharePoint Subscription Edition and SharePoint 2019; a fix for SharePoint 2016 is in progress.
  • U.S. CISA added CVE-2025-53770 to its KEV list, urging immediate remedial action.
  • FBI and U.K.’s NCSC confirmed active threats, underscoring global urgency.

What Organizations Should Do Now

  • Apply all patches including ASP.NET machine key rotation and AMSI/Defender integration
  • Isolate affected servers: disconnect from the internet if patching isn’t possible immediately
  • Assume compromise: conduct intrusion assessments, credential resets, and threat hunts on suspicious environments

Final Word

This isn’t a drill. The SharePoint zero day is being weaponized in real time. If your IT systems rely on on premises SharePoint Server especially in sectors like healthcare, education, finance, or government it’s time to act immediately. Patching alone isn’t enough. A comprehensive incident response and preventive hygiene are critical.

Stay alert. Stay protected.

For deeper updates on emerging tech threats and enterprise resilience strategies, follow StartupStoryindia

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Aman Atulya

Related Posts

India Secures Rs 1.15 Lakh Crore in Electronics Parts Investment Commitments

October 3, 2025

RapteeHV to Launch High-Voltage Electric Motorcycle T30 in November

October 3, 2025

GrowXCD Finance Raises Rs 200 Crore to Expand MSME Lending

October 1, 2025

Infra.Market Files for Confidential IPO Amid Sector Growth

October 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

From Free Deliveries to Big Dreams: The Story of Foodo

July 17, 2025112 Views

IIT Madras to Fund 100 Deeptech Startups a Year with New ₹200 Cr VC Push

July 9, 202586 Views

From Heirlooms to Headlines: AMAMA Secures $1M

July 8, 202578 Views

Forget Dry Cleaners NextWash Is Building the Swiggy of Laundry

July 16, 202576 Views
Don't Miss
Startup News

Goldman Sachs Sells ₹355 Cr in Eternal Shares in Block Deal

By Aman AtulyaOctober 4, 20250

Goldman Sachs Bank Europe SE – ODI has sold 1.08 crore shares in foodtech company…

Lenskart Gets SEBI Approval for ₹2,150 Cr IPO

October 4, 2025

BVG India’s IPO: ₹300 Cr Fresh Capital + Share Sale to Scale Business

October 3, 2025

India Secures Rs 1.15 Lakh Crore in Electronics Parts Investment Commitments

October 3, 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

Our Picks
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Startup News

Goldman Sachs Sells ₹355 Cr in Eternal Shares in Block Deal

By Aman AtulyaOctober 4, 20250

Goldman Sachs Bank Europe SE – ODI has sold 1.08 crore shares in foodtech company…

Lenskart Gets SEBI Approval for ₹2,150 Cr IPO

October 4, 2025

BVG India’s IPO: ₹300 Cr Fresh Capital + Share Sale to Scale Business

October 3, 2025

India Secures Rs 1.15 Lakh Crore in Electronics Parts Investment Commitments

October 3, 2025

Subscribe to Updates

Get the latest creative news from SmartMag about art & design.

Recent Posts

  • Goldman Sachs Sells ₹355 Cr in Eternal Shares in Block Deal
  • Lenskart Gets SEBI Approval for ₹2,150 Cr IPO
  • BVG India’s IPO: ₹300 Cr Fresh Capital + Share Sale to Scale Business
  • India Secures Rs 1.15 Lakh Crore in Electronics Parts Investment Commitments
  • Vani: The All-in-One Visual Collaboration Platform for Hybrid Workforces

Recent Comments

No comments to show.
Editors Picks

Supreme Court Stays ₹5,712 Crore GST Demand Against Paytm First Games

May 25, 2025
Top Reviews
Advertisement

Type above and press Enter to search. Press Esc to cancel.