Categories: USA

CISA Warns of New Exploit Targeting Microsoft SharePoint

Hackers Exploit Microsoft SharePoint Servers; CISA Issues Urgent Warning

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert warning organizations of an active exploitation campaign targeting on-premises Microsoft SharePoint servers. According to CISA’s July 20 report, the attack—known publicly as “ToolShell”—takes advantage of server vulnerabilities to grant attackers full access to internal systems.

“This exploitation activity… provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content,” CISA said in its July 20 report. The agency is currently assessing the full impact of the breach.

Microsoft acknowledged the threat on July 19, confirming that only on-premises servers are affected—SharePoint Online on Microsoft 365 is not at risk. Updates have been released for SharePoint Subscription Edition and SharePoint 2019, while patches for SharePoint 2016 are pending.

Both CISA and Microsoft urge system administrators to install the latest security updates, enable Antimalware Scan Interface (AMSI), and deploy Microsoft Defender for Endpoint. In cases where AMSI cannot be activated, CISA recommends temporarily disconnecting affected systems from the internet.

The exploit, listed under CVE-2025-49706, has been added to CISA’s Known Exploited Vulnerabilities catalog. Organizations are encouraged to review their logging practices, reduce administrative privileges, and follow Microsoft’s advanced mitigation strategies.

With over 200,000 organizations relying on SharePoint globally, the attack underscores growing cybersecurity challenges. CISA further warned of increasing threats to cloud infrastructure, calling for enhanced public-private cooperation to defend digital assets.

Recent Posts

Fire FC II Signs Draft Pick Jack Sandmeyer

Chicago Fire FC II has signed defender Jack Sandmeyer, the club’s 2026 MLS SuperDraft selection, to an MLS NEXT Pro…

4 days ago

Chicago Strengthens Role in Medical Research

Chicago continues to rank among the nation’s leading hubs for medical research, supported by a network of major universities, hospitals,…

5 days ago

CTA Advances $3.6B Red Line Extension

For decades, residents of Chicago’s Far South Side have watched the city’s transit map end abruptly at 95th Street. Neighborhoods…

2 weeks ago

No. 18 Saint Louis Rolls Past Loyola 86-59

No. 18 Saint Louis extended its winning streak to 18 games Friday night, pulling away in the second half for…

2 weeks ago

Chicago Office Vacancies Climb to 28.2%

Office vacancy rates in Chicago have climbed to 28.2 percent, exceeding pre-pandemic levels and marking the 14th straight quarter of…

2 weeks ago

NBC Adds Kershaw, Rizzo, Votto to MLB Broadcast Team

NBC has finalized its broadcast lineup for its return to Major League Baseball coverage this season, officially adding recently retired…

3 weeks ago

This website uses cookies.