Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Yaadhum Ariyaan Now Streaming on Aha Tamil: Everything You Need to Know About This Thriller Movie

    August 8, 2025

    Earliest Known Black Hole Found Just 500 Million Years After the Big Bang

    August 8, 2025

    Arc’s sister browser Dia launches paid plan for unlimited AI access

    August 8, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Yaadhum Ariyaan Now Streaming on Aha Tamil: Everything You Need to Know About This Thriller Movie
    • Earliest Known Black Hole Found Just 500 Million Years After the Big Bang
    • Arc’s sister browser Dia launches paid plan for unlimited AI access
    • This three-pack of fast Wi-Fi 7 routers is under $200 for the first time
    • Xbox Halts Development on Co-Op Game From Just Cause Studio, Kojima’s OD Reportedly Still in the Works
    • Want to hop on the wired earbuds trend? Here are 4 models I’d buy as an audio reviewer
    • Apple Intelligence’s ChatGPT Integration to Reportedly Get Support for GPT-5 Soon
    • Google Working on Fix for Glum Gemini, Stuck in ‘Infinite Loop’ of Self-Esteem Issues
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»Software»Hackers hijack Microsoft SharePoint flaw to unleash devastating ransomware that’s already hitting US government systems hard
    Software

    Hackers hijack Microsoft SharePoint flaw to unleash devastating ransomware that’s already hitting US government systems hard

    techupdateadminBy techupdateadminJuly 31, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • A remote code bug in SharePoint lets hackers hijack systems without even logging in
    • Storm-2603 is exploiting unpatched servers using chained bugs to gain long-term access undetected
    • ToolShell scored a perfect 10 on Bitsight’s risk scale, triggering immediate federal concern

    A critical flaw in on-premises Microsoft SharePoint Servers has escalated into a wider cybersecurity crisis, as attackers move from espionage to extortion.

    The campaign, initially traced to a vulnerability that allowed stealthy access, is now distributing ransomware, a development that adds an alarming layer of disruption to what was previously understood as a data-focused intrusion.

    Microsoft has linked this pivot to a threat actor it refers to as “Storm-2603,” and victims whose systems have been locked out must pay a ransom, typically in cryptocurrency.


    You may like

    From silent access to full-blown extortion

    At the heart of the compromise are two severe vulnerabilities, which are CVE-2025-53770, dubbed “ToolShell,” and its variant CVE-2025-53771.

    These flaws allow unauthenticated remote code execution, giving attackers control over unpatched systems simply by sending a crafted request.

    The absence of login requirements makes these exploits particularly dangerous for organizations that have delayed applying security updates.

    Experts from Bitsight claim CVE-2025-53770 scores the maximum 10 on its Dynamic Vulnerability Exploit (DVE) scale, highlighting the urgency of remediation.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Security firms have noted a sharp uptick in attacks. Eye Security, which first reported signs of compromise, estimated 400 confirmed victims, up from 100 over the weekend, and warned the actual number is likely far higher.

    “There are many more, because not all attack vectors have left artifacts that we could scan for,” said Vaisha Bernard, chief hacker for Eye Security.

    US government agencies, including the NIH and reportedly the Department of Homeland Security (DHS), have also been affected.

    In response, CISA, DHS’s cyberdefense arm, has added CVE-2025-53770 to its Known Exploited Vulnerabilities list, mandating immediate action across federal systems once patches are released.

    One strain in circulation is said to be the “Warlock” ransomware, distributed freely within compromised environments.

    The pattern of chained exploits, combining the newer CVEs with older ones like CVE-2025-49704, points to a deeper structural issue in the security of on-premises SharePoint instances.

    Attackers have reportedly managed to bypass multi-factor authentication, steal machine keys, and maintain persistent access across affected networks.

    While SharePoint Online in Microsoft 365 remains unaffected, the impact on traditional server deployments has been widespread.

    Researchers estimate over 75 to 85 servers globally have already been compromised, with affected sectors spanning government, finance, healthcare, education, telecom, and energy.

    Globally, up to 9,000 exposed services remain at risk if left unpatched.

    Organizations are strongly urged to install the latest updates, KB5002768 for Subscription Edition, KB5002754 for SharePoint 2019, and KB5002760 for SharePoint 2016.

    Microsoft also recommends rotating MachineKey values post-patching and enabling AMSI (Antimalware Scan Interface) integration with Defender Antivirus.

    Additional guidance includes scanning for signs of compromise, such as the presence of spinstall0.aspx web shells, and monitoring logs for unusual lateral movement.

    Also, some organizations are now exploring ZTNA and Business VPN models to isolate critical systems and segment access.

    However, these measures are only effective if combined with strong endpoint protection and timely patch management.

    Via Reuters

    You might also like

    Devastating Flaw government Hackers Hard hijack hitting Microsoft ransomware SharePoint Systems unleash
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleQualcomm Said to be Developing Another High-End Chipset; Could Offer Snapdragon 8 Elite-Level Performance
    Next Article UK CMA questions cloud market as Azure revenue grows
    techupdateadmin
    • Website

    Related Posts

    Software

    Earliest Known Black Hole Found Just 500 Million Years After the Big Bang

    August 8, 2025
    Software

    Apple Intelligence’s ChatGPT integration will use GPT-5 starting with iOS 26

    August 8, 2025
    Software

    Breath Work, Biohacking, and Cryotherapy: New Buzzwords for Modern Business Travelers

    August 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Apple Pencil With ‘Trackball’ Tip, Ability to Draw on Any Surface Described in Patent Document

    July 9, 20253 Views

    Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7: First Impressions

    July 9, 20253 Views

    The Bezos-funded climate satellite is lost in space

    July 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    Yaadhum Ariyaan Now Streaming on Aha Tamil: Everything You Need to Know About This Thriller Movie

    August 8, 2025

    Earliest Known Black Hole Found Just 500 Million Years After the Big Bang

    August 8, 2025

    Arc’s sister browser Dia launches paid plan for unlimited AI access

    August 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.