TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Security

SharePoint Zero-day Persists Despite Microsoft Patches

Paul Balo by Paul Balo
July 22, 2025
in Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Microsoft’s emergency fixes have not stemmed the “ToolShell” tide.
  • The critical SharePoint zero‑day (CVE‑2025‑53770, CVSS 9.8) is still being weaponised to plant a tiny ASPX back‑door on unpatched servers, and incident‑response teams continue to log fresh...
  • Redmond’s out‑of‑band updates published 19 July cover SharePoint Subscription Edition (KB 5002768) and SharePoint 2019 (KB 5002754), but SharePoint 2016 remains exposed, leaving thousands of on‑prem deployments reliant on a stop‑gap PowerShell script...

Microsoft’s emergency fixes have not stemmed the “ToolShell” tide. The critical SharePoint zero‑day (CVE‑2025‑53770, CVSS 9.8) is still being weaponised to plant a tiny ASPX back‑door on unpatched servers, and incident‑response teams continue to log fresh intrusions daily. Redmond’s out‑of‑band updates published 19 July cover SharePoint Subscription Edition (KB 5002768) and SharePoint 2019 (KB 5002754), but SharePoint 2016 remains exposed, leaving thousands of on‑prem deployments reliant on a stop‑gap PowerShell script while attackers probe every internet‑facing portal they can find. 

SecurityWeek and Rapid7 say the campaign has already breached more than 75 organisations across finance, defence and higher‑education; telemetry shows ToolShell callers beaconing from IP ranges in Russia and Vietnam, with follow‑on payloads that dump LSASS, steal machine keys and pivot laterally.  In several cases the threat actor re‑entered even after administrators installed July’s cumulative updates, because the attackers had exfiltrated cryptographic material that let them mint new authentication cookies at will. Experts therefore stress that patching must be paired with machine‑key rotation and credential resets. 

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE‑2025‑53770 to its Known Exploited Vulnerabilities (KEV) catalogue, giving federal agencies 48 hours to apply Microsoft’s mitigations or disconnect affected servers. CISA’s alert notes that ToolShell exploits a deserialisation flaw in SharePoint’s workflow engine, requires no authentication and grants SYSTEM‑level code‑execution on successful hit. 

Also worth reading
Microsoft Cloud Growth Jumps As Azure Gives AI Spending A Better Answer Microsoft Launches MAI-Cyber-1-Flash As AI Security Becomes A Model Race Cyera Buys Oasis Security For $1B As AI Agents Create New Identity Risks OpenAI Says Rogue Agent Also Breached Other Services After Hugging Face Incident NVIDIA Launches Open Secure AI Alliance To Make Open Models A Cyber Defence Tool Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand

Microsoft’s interim guidance for vulnerable SharePoint 2016 boxes boils down to four actions: (1) install all July security updates, (2) run the hardening script that blocks remote procedure calls to suspect endpoints, (3) enable AMSI‑based scanning in Defender for Endpoint, and (4) rotate machine keys and reboot IIS. Redmond says the 2016 patch is “in final validation” and should land “within days,” but has not committed to a firm date. 

Detection teams should hunt for newly created ToolShell.aspx, spinstall0.aspx or similarly named files in /_layouts/15 and review logs for the user‑agent string toolshell‑loader/1.3 or outbound traffic to 94.103.9[.]0/24 and 193.23.181[.]0/24. Rapid7 warns that the campaign is “deliberate and persistence‑oriented,” with operators revisiting servers to drop Cobalt Strike and Bughatch within hours of initial compromise.

Here’s the bottom line, if your SharePoint server still faces the open internet and does not have KB 5002768 or KB 5002754 (or their forthcoming 2016 equivalent) plus rotated machine keys, you remain a sitting duck. Administrators unable to patch immediately should remove public exposure, implement Microsoft’s mitigation script and comb logs for any sign ToolShell has landed—because attackers aren’t waiting for the final update, and neither should you.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • 4025691-0-97050800-1753099410-original
    Microsoft Patches SharePoint Bug, Leaves 2016…
  • Microsoft SharePoint CTA
    Microsoft Warns of Critical SharePoint Zero-day…
  • 5cdb1bc21ea851eb0c74bf693121f711
    Chinese Hackers Exploiting SharePoint Zero-day - Microsoft
  • sharepoint-stock-image
    Hackers Team Up to Attack Microsoft SharePoint Systems
  • Azure-logo.png
    Azure Outage Blocks Access to Microsoft 365 and…
  • powershell-1024x683
    Microsoft Drops PowerShell 2.0 from Windows 11 & Server
  • microsoft_exchange_1500
    Microsoft Ending Exchange 2016 & 2019 Support in 30 Days
  • winUpdate-2
    Microsoft Fixes 77 Vulnerabilities in March Patch Tuesday
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: cybersecuritymicrosoftsharepointSharePoint Zero-day Vulnerability
Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Meta Revenue Beats But AI Spending And Legal Costs Hit Profit July 29, 2026
  • Microsoft Cloud Growth Jumps As Azure Gives AI Spending A Better Answer July 29, 2026
  • Russia Charges Telegram Founder Pavel Durov With Facilitating Terrorism July 29, 2026
  • Google DeepMind Reportedly Breaks Up The AlphaFold Team July 29, 2026
  • Huawei Pushes Enterprise AI Solutions In South Africa July 29, 2026
  • GoLemon Stops Taking Orders As Lagos Grocery Delivery Startup Winds Down July 29, 2026
  • Ethiopia Banking Summit Puts Digital Finance At The Centre Of Reform July 29, 2026
  • Clydestone Ghana Sues MTN Over Mobile Money IP Dispute July 29, 2026
  • DoorDash Launches DoorDash Air As It Builds Its Own Delivery Drones July 29, 2026
  • SK Hynix Posts Record AI Memory Profit But Shares Fall On High Expectations July 29, 2026
  • Cyera Buys Oasis Security For $1B As AI Agents Create New Identity Risks July 29, 2026
  • OpenAI Says Rogue Agent Also Breached Other Services After Hugging Face Incident July 29, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.