IOCs:
- 107.191.58[.]76
- 104.238.159[.]149
- 96.9.125[.]147
- Unusual POSTs to /_layouts/15/ToolPane.aspx?DisplayMode=Edit
- Unusual POSTs to /_layouts/16/ToolPane.aspx?DisplayMode=Edit
- spinstall0.aspx in SharePoint Layouts folders
Vulnerabilities:
- CVE-2025-53770 (new, no patch as of 2025-07-20)
- CVE-2025-49704 (2025-07-08 patch)
- CVE-2025-49706 (2025-07-08 patch)
Only mitigations at this time require both SharePoint AMSI integrations to be enabled and Microsoft Defender in Active mode. Other AV is not confirmed.
Also see
- https://research.eye.security/sharepoint-under-siege/
- https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-07-19-Microsoft-SharePoint-vulnerabilities-CVE-2025-49704-and-49706.txt
- https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770
- https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
- https://x.com/msftsecresponse/status/1946737930849939793
You must log in or # to comment.

