Notícia da BleepingComputer
"Sharepoint ToolShell attacks targeted orgs across four continents" #bolhasec
"Sharepoint ToolShell attacks targeted orgs across four continents" #bolhasec
Sharepoint ToolShell attacks targeted orgs across four continents
Hackers believed to be associated with China have leveraged the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint in attacks targeting government agencies, universities, telecommunicati...
www.bleepingcomputer.com
November 8, 2025 at 11:30 AM
Notícia da BleepingComputer
"Sharepoint ToolShell attacks targeted orgs across four continents" #bolhasec
"Sharepoint ToolShell attacks targeted orgs across four continents" #bolhasec
SharePoint ToolShell: Уязвимость одного запроса с удалённым выполнением кода без аутентификации
https://kripta.biz/posts/7E7287C8-67A5-4605-A768-FC1BE230261D
https://kripta.biz/posts/7E7287C8-67A5-4605-A768-FC1BE230261D
November 6, 2025 at 3:45 PM
SharePoint ToolShell: Уязвимость одного запроса с удалённым выполнением кода без аутентификации
https://kripta.biz/posts/7E7287C8-67A5-4605-A768-FC1BE230261D
https://kripta.biz/posts/7E7287C8-67A5-4605-A768-FC1BE230261D
November 6, 2025 at 3:44 PM
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
www.reddit.com
November 5, 2025 at 10:09 PM
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
ToolShell: новая масштабная угроза для SharePoint и методы защиты от неё
https://kripta.biz/posts/94D58AF0-794E-49BF-A362-073D8B8049FA
https://kripta.biz/posts/94D58AF0-794E-49BF-A362-073D8B8049FA
November 2, 2025 at 6:23 PM
ToolShell: новая масштабная угроза для SharePoint и методы защиты от неё
https://kripta.biz/posts/94D58AF0-794E-49BF-A362-073D8B8049FA
https://kripta.biz/posts/94D58AF0-794E-49BF-A362-073D8B8049FA
November 2, 2025 at 6:23 PM
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response
#Talos
blog.talosintelligence.com/ir-trends-q3...
#Talos
blog.talosintelligence.com/ir-trends-q3...
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response
Cisco Talos Incident Response observed a surge in attacks exploiting public-facing applications — mainly via ToolShell targeting SharePoint — for initial access, with post-exploitation phishing and ev...
blog.talosintelligence.com
November 1, 2025 at 12:36 AM
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response
#Talos
blog.talosintelligence.com/ir-trends-q3...
#Talos
blog.talosintelligence.com/ir-trends-q3...
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
hybrid-analysis.blogspot.com
October 31, 2025 at 4:54 PM
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
hybrid-analysis.blogspot.com
October 30, 2025 at 4:09 PM
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
hybrid-analysis.blogspot.com
October 30, 2025 at 4:09 PM
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
Author(s): Vlad Pasca Warlock ransomware was deployed by exploiting the SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 The ma...
hybrid-analysis.blogspot.com
October 30, 2025 at 3:43 PM
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction www.infosecurity-magazine.com/news/toolshe...
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction
ToolShell exploit activity surged last quarter, appearing in over 60% of Cisco Talos IR cases and driving a sharp rise in public-facing application attacks
www.infosecurity-magazine.com
October 28, 2025 at 11:12 PM
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction www.infosecurity-magazine.com/news/toolshe...
From a wave of ToolShell incidents, to a rise in post-exploitation phishing and the creative misuse of legitimate tools like Velociraptor, this episode of the TTP is packed with insights from Q3: www.youtube.com/watch?v=q7yV...
October 28, 2025 at 3:31 PM
From a wave of ToolShell incidents, to a rise in post-exploitation phishing and the creative misuse of legitimate tools like Velociraptor, this episode of the TTP is packed with insights from Q3: www.youtube.com/watch?v=q7yV...
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response blog.talosintelligence.com/ir-trends-q3...
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response
Cisco Talos Incident Response observed a surge in attacks exploiting public-facing applications — mainly via ToolShell targeting SharePoint — for initial access, with post-exploitation phishing and…
blog.talosintelligence.com
October 28, 2025 at 1:12 PM
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response blog.talosintelligence.com/ir-trends-q3...
ToolShell の普及に伴い、脅威アクターによる公開アプリのエクスプロイトが増加
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction #InfosecurityMagazine (Oct 24)
www.infosecurity-magazine.com/news/toolshe...
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction #InfosecurityMagazine (Oct 24)
www.infosecurity-magazine.com/news/toolshe...
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction
ToolShell exploit activity surged last quarter, appearing in over 60% of Cisco Talos IR cases and driving a sharp rise in public-facing application attacks
www.infosecurity-magazine.com
October 27, 2025 at 10:30 PM
ToolShell の普及に伴い、脅威アクターによる公開アプリのエクスプロイトが増加
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction #InfosecurityMagazine (Oct 24)
www.infosecurity-magazine.com/news/toolshe...
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction #InfosecurityMagazine (Oct 24)
www.infosecurity-magazine.com/news/toolshe...
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction - Infosecurity Magazine www.infosecurity-magazine.com/news/toolshe...
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction
ToolShell exploit activity surged last quarter, appearing in over 60% of Cisco Talos IR cases and driving a sharp rise in public-facing application attacks
www.infosecurity-magazine.com
October 26, 2025 at 4:56 PM
Threat Actors Ramp Up Public App Exploits as ToolShell Gains Traction - Infosecurity Magazine www.infosecurity-magazine.com/news/toolshe...
📌 China-Linked Hackers Exploit Patched ToolShell SharePoint Flaw to Breach Middle East Telecom https://www.cyberhub.blog/article/14831-china-linked-hackers-exploit-patched-toolshell-sharepoint-flaw-to-breach-middle-east-telecom
China-Linked Hackers Exploit Patched ToolShell SharePoint Flaw to Breach Middle East Telecom
China-linked hackers have exploited the ToolShell SharePoint vulnerability, tracked as CVE-2025-53770, shortly after its patch release in July 2025. This vulnerability was used to compromise a telecommunications company in the Middle East, highlighting the persistent threat posed by advanced persistent threat (APT) groups. The exploitation of a patched vulnerability underscores the critical importance of timely patch management and the evolving tactics of state-sponsored cyber actors.
The ToolShell SharePoint vulnerability, CVE-2025-53770, was addressed by Microsoft in their July 2025 security updates. However, the successful exploitation of this flaw by Chinese hackers suggests that either the affected organization had not applied the patch in a timely manner or that the attackers had developed a method to bypass the patch. This incident serves as a stark reminder of the challenges organizations face in maintaining robust cybersecurity defenses, particularly against sophisticated adversaries.
The breach of a telecommunications company in the Middle East is particularly concerning due to the strategic importance of such infrastructure. Telecommunications networks are critical for national security and economic stability, making them prime targets for state-sponsored cyber espionage and sabotage. The involvement of Chinese hackers indicates a potential geopolitical motive, as such attacks are often aimed at gathering intelligence or disrupting critical services.
From a technical perspective, the exploitation of CVE-2025-53770 likely involved sophisticated techniques to bypass security measures. Organizations must prioritize patch management and implement additional security controls, such as network segmentation, intrusion detection systems, and regular security audits. Furthermore, continuous monitoring for signs of exploitation and timely threat intelligence sharing can help mitigate the risks posed by such advanced threats.
In conclusion, the exploitation of the patched ToolShell SharePoint vulnerability by China-linked hackers highlights the ongoing challenges in cybersecurity. Organizations must remain vigilant, ensure timely patch management, and adopt a multi-layered security approach to defend against advanced threats. This incident also underscores the need for international cooperation in addressing state-sponsored cyber threats and protecting critical infrastructure.
www.cyberhub.blog
October 26, 2025 at 11:20 AM
📌 China-Linked Hackers Exploit Patched ToolShell SharePoint Flaw to Breach Middle East Telecom https://www.cyberhub.blog/article/14831-china-linked-hackers-exploit-patched-toolshell-sharepoint-flaw-to-breach-middle-east-telecom
中国系ハッカーが修正済みのToolShellの脆弱性を悪用し中東の通信事業者に侵入
中国に関連する脅威アクターは、2025年7月にマイクロソフトが対処した後、 CVE-2025-53770として追跡されているToolShell SharePointの欠陥の脆弱性を悪用して中東の通信会社に侵入しました。
「中国を拠点とする攻撃者は、ToolShell の脆弱性 ( CVE-2025-53770 ) が 2025 年 7 月に公開され修正された直後に、この脆弱性を利用して中東の通信会社を侵害しました。」とBroadcom の Symantec Threat Hunter チームが公開した...
中国に関連する脅威アクターは、2025年7月にマイクロソフトが対処した後、 CVE-2025-53770として追跡されているToolShell SharePointの欠陥の脆弱性を悪用して中東の通信会社に侵入しました。
「中国を拠点とする攻撃者は、ToolShell の脆弱性 ( CVE-2025-53770 ) が 2025 年 7 月に公開され修正された直後に、この脆弱性を利用して中東の通信会社を侵害しました。」とBroadcom の Symantec Threat Hunter チームが公開した...
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after it was patched in July.
securityaffairs.com
October 25, 2025 at 8:58 PM
中国系ハッカーが修正済みのToolShellの脆弱性を悪用し中東の通信事業者に侵入
中国に関連する脅威アクターは、2025年7月にマイクロソフトが対処した後、 CVE-2025-53770として追跡されているToolShell SharePointの欠陥の脆弱性を悪用して中東の通信会社に侵入しました。
「中国を拠点とする攻撃者は、ToolShell の脆弱性 ( CVE-2025-53770 ) が 2025 年 7 月に公開され修正された直後に、この脆弱性を利用して中東の通信会社を侵害しました。」とBroadcom の Symantec Threat Hunter チームが公開した...
中国に関連する脅威アクターは、2025年7月にマイクロソフトが対処した後、 CVE-2025-53770として追跡されているToolShell SharePointの欠陥の脆弱性を悪用して中東の通信会社に侵入しました。
「中国を拠点とする攻撃者は、ToolShell の脆弱性 ( CVE-2025-53770 ) が 2025 年 7 月に公開され修正された直後に、この脆弱性を利用して中東の通信会社を侵害しました。」とBroadcom の Symantec Threat Hunter チームが公開した...
Warlock Ransomware Actors exploiting Sharepoint ToolShell Zero-Day Vulnerability in new Attack Wave:
potatosecuritynews.com/warlock-rans...
potatosecuritynews.com/warlock-rans...
October 25, 2025 at 2:15 PM
Warlock Ransomware Actors exploiting Sharepoint ToolShell Zero-Day Vulnerability in new Attack Wave:
potatosecuritynews.com/warlock-rans...
potatosecuritynews.com/warlock-rans...
Warlock Ransomware Actors exploiting Sharepoint ToolShell Zero-Day Vulnerability in new Attack Wave:
cybersecuritynews.com/warlock-rans...
cybersecuritynews.com/warlock-rans...
October 25, 2025 at 7:58 AM
Warlock Ransomware Actors exploiting Sharepoint ToolShell Zero-Day Vulnerability in new Attack Wave:
cybersecuritynews.com/warlock-rans...
cybersecuritynews.com/warlock-rans...
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch. China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, t…
#hackernews #microsoft #news
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch. China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, t…
#hackernews #microsoft #news
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch. China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, tracked as CVE-2025-53770, to breach a telecommunications company in the Middle East after it was addressed by Microsoft in July 2025. “China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in […]
securityaffairs.com
October 25, 2025 at 6:30 AM
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch. China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, t…
#hackernews #microsoft #news
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after its July patch. China-linked threat actors exploited the ToolShell SharePoint flaw vulnerability, t…
#hackernews #microsoft #news
Alert: Warlock ransomware exploits SharePoint ToolShell zero-day (CVE-2025-53770) in global attacks. Ensure systems are patched and security measures are up-to-date. #CyberSecurity #Ransomware #SharePoint Link: thedailytechfeed.com/warlock-rans...
October 25, 2025 at 6:30 AM
Alert: Warlock ransomware exploits SharePoint ToolShell zero-day (CVE-2025-53770) in global attacks. Ensure systems are patched and security measures are up-to-date. #CyberSecurity #Ransomware #SharePoint Link: thedailytechfeed.com/warlock-rans...
Warlock Ransomware Actors Exploiting Sharepoint ToolShell Zero-Day Vulnerability in New Attack Wave
Warlock Ransomware Actors Exploiting Sharepoint ToolShell Zero-Day Vulnerability in New Attack Wave
cybersecuritynews.com
October 24, 2025 at 6:17 PM
Warlock Ransomware Actors Exploiting Sharepoint ToolShell Zero-Day Vulnerability in New Attack Wave
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-linked threat actors exploited the ToolShell SharePoint vulnerability (CVE-2025-53770) to breach a Middle Eastern telecom co... https://kiledjian.com/2025/10/24/chinalinked-hackers-exploit-patched-toolshell.html
China-linked threat actors exploited the ToolShell SharePoint vulnerability (CVE-2025-53770) to breach a Middle Eastern telecom co... https://kiledjian.com/2025/10/24/chinalinked-hackers-exploit-patched-toolshell.html
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-based threat actors exploited ToolShell SharePoint flaw CVE-2025-53770 soon after it was patched in July.
securityaffairs.com
October 24, 2025 at 1:33 PM
China-linked hackers exploit patched ToolShell flaw to breach Middle East telecom
China-linked threat actors exploited the ToolShell SharePoint vulnerability (CVE-2025-53770) to breach a Middle Eastern telecom co... https://kiledjian.com/2025/10/24/chinalinked-hackers-exploit-patched-toolshell.html
China-linked threat actors exploited the ToolShell SharePoint vulnerability (CVE-2025-53770) to breach a Middle Eastern telecom co... https://kiledjian.com/2025/10/24/chinalinked-hackers-exploit-patched-toolshell.html
Chinese threat actors exploited the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint, targeting a Middle Eastern telecom and various government entities across Africa and South America, as well as a U.S. university.
Chinese Threat Actors Exploit ToolShell SharePoint Flaw Weeks After Microsoft's July Patch
thehackernews.com
October 24, 2025 at 11:32 AM
Chinese threat actors exploited the ToolShell vulnerability (CVE-2025-53770) in Microsoft SharePoint, targeting a Middle Eastern telecom and various government entities across Africa and South America, as well as a U.S. university.