What to know about ToolShell, the SharePoint threat under mass exploitation

What to know about ToolShell, the SharePoint threat under mass exploitation

In the past four days, both government agencies and private sector organizations have found themselves in a precarious situation due to a severe vulnerability in SharePoint, Microsoft’s popular document-sharing platform. The revelation of this critical flaw has led to significant attacks that are challenging to monitor as they unfold. So, what exactly is SharePoint? This server software, in use since 2001, serves as a vital tool for companies to store, manage, and share internal documents, primarily within their intranets. According to Microsoft, the platform boasts around 200 million users as of 2020, and by last year, over 400,000 organizations had adopted it, with approximately 80% classified as Fortune 500 companies. The vulnerability itself, officially designated as CVE-2025-53770, allows for unauthenticated remote code execution on SharePoint servers. This flaw is particularly alarming, rated at a severity of 9.8 out of 10, due to its potential for significant damage. It permits attackers, who have no system rights, to execute malicious code remotely. The first signs of exploitation were identified by Eye Security, which reported that the flaw had been actively targeted in two distinct waves, starting just a day before its discovery. The firm later updated its estimates, indicating that around 400 systems globally had been compromised, including networks associated with the US National Nuclear Security Administration.

Sources : Ars Technica

Published On : Jul 23, 2025, 20:15

AI
Uber Targets AI Growth, Slashes Hiring Amid Code Innovations

Uber is making a strategic shift towards artificial intelligence, leading to a slowdown in new hiring. During the first-...

Business Insider | May 06, 2026, 13:50
Uber Targets AI Growth, Slashes Hiring Amid Code Innovations
Automotive
Rivian Expands its Horizon with New R2 Electric SUV Variants

Excitement is building as Rivian prepares to unveil its highly anticipated R2 electric SUV. Following the success of its...

Ars Technica | May 06, 2026, 12:51
Rivian Expands its Horizon with New R2 Electric SUV Variants
Computing
Nvidia and Corning Forge Strategic Alliance to Revolutionize AI Infrastructure

Nvidia, a leading player in the artificial intelligence sector, has joined forces with Corning, renowned for its glass m...

CNBC | May 06, 2026, 11:55
Nvidia and Corning Forge Strategic Alliance to Revolutionize AI Infrastructure
Startups
Last Chance: Grab Your 50% Discount for TechCrunch Disrupt 2026

Time is running out! You have just three days left to secure your spot at TechCrunch Disrupt 2026, happening from Octobe...

TechCrunch | May 06, 2026, 14:30
Last Chance: Grab Your 50% Discount for TechCrunch Disrupt 2026
AI
Apple Agrees to $250 Million Settlement Over Siri Feature Delays for iPhone Users

Apple has agreed to a settlement exceeding $250 million to resolve a lawsuit concerning the misleading promotion of Siri...

Business Today | May 06, 2026, 09:30
Apple Agrees to $250 Million Settlement Over Siri Feature Delays for iPhone Users
View All News