Another massive security snafu hits Microsoft
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Microsoft faces another major security breach as attackers exploit a critical zero-day vulnerability (CVE-2025-53770) in SharePoint Server, dubbed "ToolShell." The flaw allows complete server takeover and affects thousands of organizations globally, including government agencies and critical infrastructure. Despite patches for newer versions, SharePoint 2016 remains unpatched. Security experts attribute the attacks to nation-state actors, with exploitation beginning July 7 and intensifying mid-July. The vulnerability enables data exfiltration, backdoor deployment, and cryptographic key theft, with researchers warning that patching alone is insufficient for full remediation.
Sort: