Categories: USA

CISA Warns of New Exploit Targeting Microsoft SharePoint

Hackers Exploit Microsoft SharePoint Servers; CISA Issues Urgent Warning

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert warning organizations of an active exploitation campaign targeting on-premises Microsoft SharePoint servers. According to CISA’s July 20 report, the attack—known publicly as “ToolShell”—takes advantage of server vulnerabilities to grant attackers full access to internal systems.

“This exploitation activity… provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content,” CISA said in its July 20 report. The agency is currently assessing the full impact of the breach.

Microsoft acknowledged the threat on July 19, confirming that only on-premises servers are affected—SharePoint Online on Microsoft 365 is not at risk. Updates have been released for SharePoint Subscription Edition and SharePoint 2019, while patches for SharePoint 2016 are pending.

Both CISA and Microsoft urge system administrators to install the latest security updates, enable Antimalware Scan Interface (AMSI), and deploy Microsoft Defender for Endpoint. In cases where AMSI cannot be activated, CISA recommends temporarily disconnecting affected systems from the internet.

The exploit, listed under CVE-2025-49706, has been added to CISA’s Known Exploited Vulnerabilities catalog. Organizations are encouraged to review their logging practices, reduce administrative privileges, and follow Microsoft’s advanced mitigation strategies.

With over 200,000 organizations relying on SharePoint globally, the attack underscores growing cybersecurity challenges. CISA further warned of increasing threats to cloud infrastructure, calling for enhanced public-private cooperation to defend digital assets.

Recent Posts

Mets rout Nationals 8-0, seek momentum

The New York Mets capitalized on limited opportunities to deliver an 8-0 shutout victory over the Washington Nationals on Tuesday…

1 day ago

White Sox rally past Angels with late surge

A late offensive surge powered the Chicago White Sox to an 8-7 victory over the Los Angeles Angels on Monday…

2 days ago

O’Hare expansion begins with Concourse D milestone

Chicago has taken a major step toward transforming O’Hare International Airport, marking the start of construction on Concourse D —…

6 days ago

Diamondbacks outslug White Sox behind Vargas

Ildemaro Vargas delivered a career performance at the plate, powering the Arizona Diamondbacks to an 11-7 win over the Chicago…

1 week ago

Chicago Fire names SeatGeek stadium partner

Chicago Fire FC is moving forward with plans for its future home, announcing a multi-year partnership with SeatGeek that will…

1 week ago

Swanson homer lifts Cubs past Phillies

Dansby Swanson delivered the decisive blow as the Chicago Cubs extended their winning streak with a 5-1 victory over the…

1 week ago

This website uses cookies.