⤷ Title: ToolShell: New SharePoint RCE Zero-Day Chain Under Active Global Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 00:20:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49704 #CVE_2025_49706 #cybersecurity #exploitation #Microsoft #rce #Remote Code Execution #Sharepoint #ToolShell #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 00:20:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49704 #CVE_2025_49706 #cybersecurity #exploitation #Microsoft #rce #Remote Code Execution #Sharepoint #ToolShell #Vulnerability #zero_day
Daily CyberSecurity
ToolShell: New SharePoint RCE Zero-Day Chain Under Active Global Exploitation
An unauthenticated SharePoint RCE chain dubbed ToolShell (CVE-2025-49704, CVE-2025-49706) is being actively exploited globally, granting attackers full control of on-premise servers.
⤷ Title: Critical SharePoint Zero-Day (CVE-2025-53770) Actively Exploited in the Wild
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 07:06:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_53770 #cybersecurity #exploitation #Microsoft #RCE #remote code execution #SharePoint Server #ToolShell #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 07:06:57 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_53770 #cybersecurity #exploitation #Microsoft #RCE #remote code execution #SharePoint Server #ToolShell #vulnerability #zero_day
Penetration Testing Tools
Critical SharePoint Zero-Day (CVE-2025-53770) Actively Exploited in the Wild
A critical SharePoint zero-day (CVE-2025-53770, CVSS 9.8) is actively exploited in the wild, leveraging ToolShell to gain unauthenticated RCE on on-premises servers.
⤷ Title: SharePoint Under Siege: New Zero-Day (CVE-2025-53770) Actively Compromises 100+ Global Organizations
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 07:20:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #data breach #exploitation #Global Attack #Microsoft #RCE #SharePoint #ToolShell #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 07:20:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #data breach #exploitation #Global Attack #Microsoft #RCE #SharePoint #ToolShell #vulnerability #zero_day
Penetration Testing Tools
SharePoint Under Siege: New Zero-Day (CVE-2025-53770) Actively Compromises 100+ Global Organizations
A critical SharePoint zero-day (CVE-2025-53770) is actively exploited, compromising over 100 organizations globally by stealing cryptographic keys and enabling persistent remote access.
⤷ Title: CVE-2025–53770: A Comprehensive Analysis of the Critical SharePoint Server Vulnerability
════════════════════════
𐀪 Author: Tech Zealots - Threat & Malware Research
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 02:46:45 GMT
════════════════════════
⌗ Tags: #malware_analysis #vulnerability_analysis #cve_2025_53770 #toolshell #cybersecurity
════════════════════════
𐀪 Author: Tech Zealots - Threat & Malware Research
════════════════════════
ⴵ Time: Wed, 23 Jul 2025 02:46:45 GMT
════════════════════════
⌗ Tags: #malware_analysis #vulnerability_analysis #cve_2025_53770 #toolshell #cybersecurity
Medium
CVE-2025–53770: A Comprehensive Analysis of the Critical SharePoint Server Vulnerability
Understanding the technical details, business impact, and response strategies for the zero-day vulnerability affecting SharePoint Server…
⤷ Title: ToolShell: Microsoft SharePoint Zero-Day Chain Actively Exploited Globally – Auth Bypass & RCE Confirmed
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 23:18:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication bypass #cybersecurity #Deserialization #exploitation #Microsoft #RCE #SharePoint #ToolShell #vulnerability #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 23:18:51 +0000
════════════════════════
⌗ Tags: #Vulnerability #authentication bypass #cybersecurity #Deserialization #exploitation #Microsoft #RCE #SharePoint #ToolShell #vulnerability #zero_day
Penetration Testing Tools
ToolShell: Microsoft SharePoint Zero-Day Chain Actively Exploited Globally – Auth Bypass & RCE Confirmed
Kaspersky reports the ToolShell exploit chain (CVE-2025-49706, -49704, -53770, -53771) actively targets SharePoint servers globally, enabling unauthenticated RCE and auth bypass.
⤷ Title: The ToolShell Threat Escalates: New 4L4MD4R Ransomware Joins China-Linked APTs in SharePoint Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 02:30:19 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #4L4MD4R #China_Linked APTs #CVE_2025_49704 #CVE_2025_49706 #cybersecurity #exploitation #Microsoft #ransomware #SharePoint #ToolShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 Aug 2025 02:30:19 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #4L4MD4R #China_Linked APTs #CVE_2025_49704 #CVE_2025_49706 #cybersecurity #exploitation #Microsoft #ransomware #SharePoint #ToolShell
Penetration Testing Tools
The ToolShell Threat Escalates: New 4L4MD4R Ransomware Joins China-Linked APTs in SharePoint Attacks
A new ransomware strain, 4L4MD4R, is now exploiting the ToolShell SharePoint vulnerability chain, which is already being used by China-linked APTs to compromise hundreds of organizations globally.
⤷ Title: CISA Warns of “ToolShell”: Critical Exploit Chain Hits SharePoint Servers, Bypasses Authentication
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #cybersecurity #Exploit Chain #rce #Sharepoint #ToolShell #Vulnerability #webshell #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:42:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #cybersecurity #Exploit Chain #rce #Sharepoint #ToolShell #Vulnerability #webshell #zero_day
Daily CyberSecurity
CISA Warns of "ToolShell": Critical Exploit Chain Hits SharePoint Servers, Bypasses Authentication
CISA issues an urgent warning about "ToolShell," a sophisticated exploit chain targeting SharePoint servers with multiple vulnerabilities to install webshells and steal crypto keys.
⤷ Title: ToolShell Exploit: China-Linked Hackers Target Global Critical Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 09:36:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China_linked #Critical Infrastructure #RCE #SharePoint #ToolShell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 27 Oct 2025 09:36:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China_linked #Critical Infrastructure #RCE #SharePoint #ToolShell
Penetration Testing Tools
ToolShell Exploit: China-Linked Hackers Target Global Critical Infrastructure
Hackers exploited the ToolShell SharePoint RCE flaw (CVE-2025-53770) to deploy Zingdoor and ShadowPad in attacks on global telecom and government targets.
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.