CISA Warns of New Exploit Targeting Microsoft SharePoint

CISA Warns of New Exploit Targeting Microsoft SharePoint

Hackers Exploit Microsoft SharePoint Servers; CISA Issues Urgent Warning

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert warning organizations of an active exploitation campaign targeting on-premises Microsoft SharePoint servers. According to CISA’s July 20 report, the attack—known publicly as “ToolShell”—takes advantage of server vulnerabilities to grant attackers full access to internal systems.

“This exploitation activity… provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content,” CISA said in its July 20 report. The agency is currently assessing the full impact of the breach.

Microsoft acknowledged the threat on July 19, confirming that only on-premises servers are affected—SharePoint Online on Microsoft 365 is not at risk. Updates have been released for SharePoint Subscription Edition and SharePoint 2019, while patches for SharePoint 2016 are pending.

Both CISA and Microsoft urge system administrators to install the latest security updates, enable Antimalware Scan Interface (AMSI), and deploy Microsoft Defender for Endpoint. In cases where AMSI cannot be activated, CISA recommends temporarily disconnecting affected systems from the internet.

The exploit, listed under CVE-2025-49706, has been added to CISA’s Known Exploited Vulnerabilities catalog. Organizations are encouraged to review their logging practices, reduce administrative privileges, and follow Microsoft’s advanced mitigation strategies.

With over 200,000 organizations relying on SharePoint globally, the attack underscores growing cybersecurity challenges. CISA further warned of increasing threats to cloud infrastructure, calling for enhanced public-private cooperation to defend digital assets.

Related Posts
Chicago Proposes First-in-Nation Social Media ‘SMART Tax’
Chicago Mayor Brandon Johnson has introduced a new tax proposal targeting major social media companies
Chicago Teachers Union, CPS Reach $1.5B Deal Without Strike
The Chicago Teachers Union and Chicago Public Schools have reached a $1.5 billion, four-year contract
Early Bird Flu Surge Hits Europe, North America Hard
Europe and North America are confronting an unusually early and intense surge of bird flu,
Chicago Fire, Versiti Partner for Community Blood Drive
Chicago Fire FC and the Versiti Blood Center of Illinois are partnering to host the
Turkey Adoption Programs Grow as Sanctuaries Shift Tradition
A growing number of farm animal sanctuaries across the country are promoting an alternative Thanksgiving
Magic Look to Extend Momentum in Matchup vs. Bulls
After advancing to the final eight of the NBA Cup, the Orlando Magic hope their
Patriots Face Giants Minus Two Starters on Offensive Line
The New England Patriots haven’t faced much adversity this season, but they will on Monday
Starbucks Strike Expands as Workers Press for Contract
Thousands of baristas at nearly 100 Starbucks locations are on strike this holiday season, picketing
CTA Attack Spurs Renewed Demands for Transit Safety Reform
A brutal attack at one of Chicago’s busiest transit hubs has reignited concerns about safety
Chicago Fire Names Zinckernagel MVP in 2025 Awards
Chicago Fire FC has announced its 2025 Team Award winners, recognizing Philip Zinckernagel as Most