• Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

Epstein Files Reveal Peter Thiel’s Elaborate Dietary Restrictions

February 7, 2026

The Tech Elites in the Epstein Files

February 6, 2026

Mistral’s New Ultra-Fast Translation Model Gives Big AI Labs a Run for Their Money

February 5, 2026
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
UptownBudget
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
UptownBudget
Home » Microsoft Confirms Ongoing Mass SharePoint Attack — No Patch Available
Innovation

Microsoft Confirms Ongoing Mass SharePoint Attack — No Patch Available

adminBy adminJuly 20, 20250 ViewsNo Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Microsoft users are, once again, under attack. This time, the threat is not restricted to Outlook users, or involves a Windows browser-based security bypass, and unlike the recent Windows authentication relay attack vulnerability, there is no patch, no magic update, to remedy this one. Which is bad news for Microsoft SharePoint Server users, as CVE-2025-53770 is currently under confirmed “mass attack” and on-premises servers across the world are being compromised. Here’s what you need to know and do.

Microsoft Confirms CVE-2025-53770 SharePoint Server Attacks

It’s been quite the few weeks for security warnings, what with Amazon informing 220 million customers of Prime account attacks, and claims of a mass hack of Ring doorbells going viral. The first of those can be mitigated by basic security hygiene, and the latter appears to be a false alarm. The same cannot be said for CVE-2025-53770, a newly uncovered and confirmed attack against users of SharePoint Server which is currently undergoing mass exploitation on a global level, according to the Eye Research experts who discovered it. Microsoft, meanwhile, has admitted that not only is it “aware of active attacks” but, worryingly, “a patch is currently not available for this vulnerability.”

CVE-2025-53770, which is also being called ToolShell, is a critical vulnerability in on-premises SharePoint. The end result of which is the ability for attackers to gain access and control of said servers without authentication. If that sounds bad, it’s because it is. Very bad indeed.

“The risk is not theoretical,” the researchers warned, “attackers can execute code remotely, bypassing identity protections such as MFA or SSO.” Once they have, they can then “access all SharePoint content, system files, and configurations and move laterally across the Windows Domain.”

And then there’s the theft of cryptographic keys. That can enable an attacker to “impersonate users or services,” according to the report, “even after the server is patched.” So, even when a patch is eventually released, and I would expect an emergency update to arrive fairly quickly for this one, the problem isn’t solved. You will, it was explained, “need to rotate the secrets allowing all future tokens that can be created by the malicious actor to become invalid.”

And, of course, as SharePoint will often connect to other core services, including the likes of Outlook and Teams, oh and not forgetting OneDrive, the threat, if exploited, can and will lead to “data theft, password harvesting, and lateral movement across the network,” the researchers warned.

Mitigating The Microsoft SharePoint Server Attacks

While the Microsoft Security Response Center has stated that it is “actively working to release a security update,” and will “provide additional details as they are available,” there is no patch at the time of writing. In the meantime, it advised that customers should apply the following mitigations:”

Configure Antimalware Scan Interface integration in SharePoint and deploy Defender AV on all SharePoint servers. “If you cannot enable AMSI,” Microsoft said, “we recommend you consider disconnecting your server from the internet until a security update is available.”

I have approached Microsoft for a statement and will update this story with any further developments.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

A Robotaxi Hit A Child. Here’s What We Know

Innovation January 29, 2026

Apple Suddenly Releases Surprise iPhone Update With Features And Fixes

Innovation January 28, 2026

‘Arc Raiders’ Just Added 2 Powerful New Items In Latest Update

Innovation January 27, 2026

Two App Updates Make The Apple Watch Even Better For Fitness Tracking

Innovation January 26, 2026

A New Paradigm For AI Decision Making

Innovation January 25, 2026

A Psychologist Shares Your Science-Backed Horoscope—Here’s What Yours Says About You

Innovation January 24, 2026
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Epstein Files Reveal Peter Thiel’s Elaborate Dietary Restrictions

February 7, 2026

The Tech Elites in the Epstein Files

February 6, 2026

Mistral’s New Ultra-Fast Translation Model Gives Big AI Labs a Run for Their Money

February 5, 2026

ICE Asks Companies About ‘Ad Tech and Big Data’ Tools It Could Use in Investigations

February 3, 2026

TikTok Data Center Outage Triggers Trust Crisis for New US Owners

February 2, 2026

Latest Posts

Moltbot Is Taking Over Silicon Valley

January 31, 2026

China’s Renewable Energy Revolution Is a Huge Mess That Might Save the World

January 29, 2026

A Robotaxi Hit A Child. Here’s What We Know

January 29, 2026

Meta Seeks to Bar Mentions of Mental Health—and Zuckerberg’s Harvard Past—From Child Safety Trial

January 28, 2026

Apple Suddenly Releases Surprise iPhone Update With Features And Fixes

January 28, 2026
Advertisement
Demo

UptownBudget is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2026 UptownBudget. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.