Don’t do SECURITY. Do business SECURELY.

SharePoint zero-day exploited in wave of attacks on organisations

Attackers exploit a zero-day flaw in on-premises Microsoft SharePoint servers, known as ToolShell, with hundreds of organisations reported compromised.

Microsoft warned of active attacks exploiting a zero-day vulnerability, CVE-2025-53770, in on-premises SharePoint Server. The exploit chain, known as ToolShell, let attackers run code and steal cryptographic machine keys from unpatched servers.

What happened

  • Dutch firm Eye Security detected large-scale exploitation on the evening of 18 July 2025, Microsoft later said it had seen exploitation attempts from 7 July, and CISA added the flaw to its known exploited vulnerabilities catalogue on 20 July.
  • Microsoft said it had observed Chinese state actors it tracks as Linen Typhoon and Violet Typhoon, and a China-based group it calls Storm-2603, exploiting the flaws.
  • Hundreds of organisations were reported to have been compromised, including US government agencies.
  • Stolen machine keys meant that patching alone was not enough, and Microsoft and CISA advised rotating keys and restarting IIS.

Why it mattered

It showed how quickly state and criminal actors can exploit flaws in widely used, internet-facing business software. Organisations still running on-premises collaboration servers found themselves exposed within hours of the first attacks.

Lessons for organisations

Keep an accurate inventory of internet-facing systems and patch emergency advisories urgently. After a compromise, rotate secrets and hunt for persistence, because patching alone may not remove attackers. Consider whether moving to supported cloud services would reduce the patching burden.

Sources: Microsoft Security, CISA

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights