• News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Commerce & Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
Monday, December 22, 2025
  • Login
No Result
View All Result
NEWSLETTER
Tech | Business | Economy
  • News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Commerce & Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
  • Chidiverse
  • News
  • Tech
    • DisruptiveTECH
    • ConsumerTech
    • How To
    • TechTAINMENT
  • Business
    • Telecoms
    • Commerce & Mobility
    • Environment
    • Travel
    • StartUPs
      • Chidiverse
    • TE Insights
    • Security
  • Partners
  • Economy
    • Finance
    • Fintech
    • Digital Assets
    • Personal Finance
    • Insurance
  • Features
    • IndustryINFLUENCERS
    • Guest Writer
    • EventDIARY
    • Editorial
    • Appointment
  • TECHECONOMY TV
  • Apply
  • TBS
  • BusinesSENSE For SMEs
  • Chidiverse
No Result
View All Result
Tech | Business | Economy
No Result
View All Result
  • News
  • Finance
  • StartUPs
  • TechTAINMENT
  • Guest Writer
  • Digital Assets
  • IndustryINFLUENCERS
  • Environment
  • Macro Monday
ADVERTISEMENT

Home » Microsoft Warns of Active Zero-Day Attacks Targeting SharePoint Servers

Microsoft Warns of Active Zero-Day Attacks Targeting SharePoint Servers

Joan Aimuengheuwa by Joan Aimuengheuwa
July 21, 2025
in Security
Reading Time: 2 mins read
1
Microsoft Warns of attacks on SharePoint Servers

Microsoft Warns of cyber attack

RelatedPosts

NCS Warns FIRS-France Deal Must Not Compromise Nigeria’s Digital Sovereignty

REPORT: Hackers Using AI‑Generated Websites as Attack Tools

REPORT: Cybercriminals Using Popular Turkish, Arabic eBooks as Bait to Steal Personal Data

UBA
Advertisements

Microsoft has sounded the alarm over ongoing cyberattacks targeting its SharePoint server software, warning that systems across government agencies, banks, hospitals, and universities are now exposed to severe compromise.

The company confirmed that hackers are exploiting a flaw tracked as CVE-2025-53770—a zero-day vulnerability rated 9.8 out of 10 in severity. In simple terms, attackers don’t need passwords or insider access; they can remotely take over servers using this flaw.

The attack chain, which security researchers have labelled “ToolShell,” is alarmingly effective. It enables cybercriminals to circumvent identity protections, such as multi-factor authentication (MFA) and single sign-on (SSO). 

According to Microsoft, at least 85 servers in 29 organisations globally have already been breached. Affected entities span sensitive sectors: government agencies, financial institutions, hospitals, and universities.

In a direct message to affected customers, Microsoft said: “We’ve been coordinating closely with CISA, DOD Cyber Defense Command and key cybersecurity partners globally throughout our response.”

Here’s how the attack works. Hackers plant a malicious ASPX file, named examples include ‘spinstallo.aspx’, on target servers. Once in place, this file extracts machine key configurations, allowing attackers to forge tokens and execute arbitrary code. 

The result is total control of the compromised system. They can steal cryptographic keys, embed backdoors for persistent access, and deploy further malware undetected.

For those unaware, SharePoint servers are widely used by corporations and governments to share documents internally. While Microsoft’s cloud-based SharePoint Online remains unaffected, its on-premises versions from 2016, 2019, and the Subscription Edition are dangerously exposed.

MTN New

In plain terms, Microsoft is telling organisations: patch your servers now or risk being hijacked.

The company has issued July 2025 security updates and strongly advised enabling the Antimalware Scan Interface (AMSI) alongside Defender Antivirus. If enabling AMSI is not possible, Microsoft recommends disconnecting servers from the internet entirely until patches are applied.

Additionally, Microsoft recommends rotating ASP.NET machine keys and restarting IIS servers to block ongoing attacks.

Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated its response, adding CVE-2025-53770 to its Known Exploited Vulnerabilities catalogue. U.S. federal agencies have been ordered to patch their servers by July 21, 2025.

The FBI acknowledged the attacks in a brief statement on Sunday, saying it is “aware of the attacks and is working closely with its federal and private-sector partners,” but declined to provide further details.

What makes this breach more worrying is the sophisticated nature of the exploit. According to the initial disclosure by security experts at the Pwn2Own Berlin 2025 event, the ToolShell attack combines two additional vulnerabilities (CVE-2025-49706 and CVE-2025-49704), making it harder to detect and stop.

For organisations yet to patch, the advice is to isolate your servers or risk a full-scale breach.

Cybersecurity professionals globally now face a race against time to close the security gaps before more damage is done.

0Shares

stanbic
Joan Aimuengheuwa

Joan Aimuengheuwa

Joan thrives at helping individuals and businesses scale via storytelling...

Related Posts

Muhammad Sirajo Aliyu Takes Over as the 15th President of Nigeria Computer Society - NCS | FIRS-France

NCS Warns FIRS-France Deal Must Not Compromise Nigeria’s Digital Sovereignty

by Peter Oluka
December 20, 2025
0
0

On December 10, 2025, a handshake between the Federal Inland Revenue Service (FIRS) and France’s tax authority (DGFiP) signaled a...

AI-generated websites

REPORT: Hackers Using AI‑Generated Websites as Attack Tools

by Peter Oluka
December 17, 2025
0
0

Kaspersky has detected a malicious campaign, where attackers leverage AI-generated websites to distribute versions of the legitimate remote access tool...

Cybercriminals Using Popular Turkish, Arabic Books as Bait to Steal Personal Data

REPORT: Cybercriminals Using Popular Turkish, Arabic eBooks as Bait to Steal Personal Data

by Peter Oluka
December 17, 2025
0
0

The Kaspersky Global Research & Analysis Team has uncovered a malware-as-a-service campaign targeting ebook readers across Turkey, Egypt, Bangladesh and...

Nigeria Hit by 4,200 Weekly Cyberattacks as Africa’s Threats Surge

Nigeria Records 4,200 Weekly Cyberattacks Per Organisation as Africa Faces One of the World’s Highest Threat Levels

by Joan Aimuengheuwa
December 16, 2025
0
0

The data places Nigeria at the centre of a continental problem.

Sophos MITRE ATT&CK Evaluations

Sophos XDR Delivers 100% Detection Coverage in the Latest MITRE ATT&CK Evaluation

by Destiny Eseaga
December 13, 2025
0
0

Sophos, a global leader of innovative security solutions for defeating cyberattacks, has announced its best-ever results in the MITRE ATT&CK...

Businesses Turn to Cyber Insurance as AI-Driven Attacks Surge in 2025

Businesses Turn to Cyber Insurance as AI-Driven Attacks Surge in 2025

by Joan Aimuengheuwa
December 10, 2025
0
0

The global cyber insurance market has reached $20.56 billion in 2025.

Load More
Next Post
Bitget Annual Trading Competition KCGI

Bitget Annual Trading Competition KCGI Launches with $6 Million Prize Pool

Comments 1

  1. Sistem Informasi says:
    5 months ago

    How are hackers exploiting the CVE-2025-53770 flaw in SharePoint servers, and what steps is Microsoft taking to protect affected organizations worldwide? Regard Sistem Informasi

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

MTN New
UBA
Advertisements
  • About Us
  • Advertise
  • Careers
  • Contact Us

© 2025 TECHECONOMY.

No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • Politics
  • Business
  • Science
  • Tech
  • Entertainment
  • Lifestyle

© 2025 TECHECONOMY.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.