SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Reading: Microsoft SharePoint zero-day breach hits on-prem servers
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > Software > Microsoft SharePoint zero-day breach hits on-prem servers
Software

Microsoft SharePoint zero-day breach hits on-prem servers

News Room
Last updated: July 21, 2025 12:31 pm
News Room
Share
1 Min Read
SHARE

As part of the exploitation, attackers upload a file named “spinstall0.aspx,” which is used to steal the Microsoft SharePoint server’s MachineKey configuration, including the ValidationKey and DecryptionKey, security researchers reported. “Once this cryptographic material is leaked, the attacker can craft fully valid, signed __VIEWSTATE payloads,” Eye Security explained in its analysis.

Dutch cybersecurity firm Eye Security, which first identified the mass exploitation campaign, discovered the attacks began systematically targeting vulnerable servers on July 18, around 6:00 PM Central European Time. “Within hours, we identified more than dozens of separate servers compromised using the exact same payload at the same filepath,” Eye Security researchers said in their analysis.

The severity of the threat prompted rapid federal action, with CISA adding CVE-2025-53770 to its Known Exploited Vulnerabilities catalog on Sunday, just two days after active exploitation was confirmed. “BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats,” the agency noted in its advisory, giving federal agencies until July 21 to implement mitigations.

Read the full article here

You Might Also Like

What we know so far about Apple’s Liquid Glass UI – Computerworld

Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP

That ‘One Big Beautiful Bill’ ties genAI deregulation to broadband funding – Computerworld

Cloudflare offers to make AI pay to crawl websites – Computerworld

Ingram Micro’s IT outage stretches into second day – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

News

Controversial crypto billionaire is finally cleared to take his $28M trip on Blue Origin’s rocket ship

July 21, 2025
Games

DICE finally proves it’s listening to fans, will let Battlefield 6 beta players have classic class weapons

July 21, 2025

Madrona’s Matt McIlwain called it: A year later, Microsoft and Amazon are outpacing Apple

July 21, 2025
Software

As AI agents go mainstream, companies lean into confidential computing for data security – Computerworld

July 21, 2025
AI

The first traces of GPT-5 have appeared – Computerworld

July 21, 2025
Games

Abiotic Factor 1.0 release date—When to expect Cold Fusion’s new story, upgrades, and traders in your timezone

July 21, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?