Microsoft SharePoint Zero-Day: 85 Servers Hacked, No Patch in Sight!

Microsoft SharePoint’s zero-day vulnerability, CVE-2025-53770, is causing a ruckus with at least 85 compromised servers worldwide. While Microsoft races to create a patch, they suggest enabling AMSI integration and deploying Defender AV. Remember, if your server’s been acting like a diva with suspicious files, it might be time for a digital intervention!

Pro Dashboard

Hot Take:

Who knew SharePoint was the new Wild West? It seems Microsoft’s digital filing cabinet has swung open, making it the hottest ticket in town for hackers with a penchant for zero-day exploits. If you’re using SharePoint, you might want to check if your server’s been moonlighting as a hacker’s playground!

Key Points:

  • Critical zero-day vulnerability in Microsoft SharePoint, CVE-2025-53770, being actively exploited since July 18th.
  • No current patch available; at least 85 servers compromised worldwide.
  • Microsoft recommends enabling AMSI integration and deploying Defender AV to mitigate attacks.
  • Exploitation involves uploading a malicious file that targets SharePoint’s MachineKey configuration.
  • Organizations affected include multi-nationals and government entities.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?