
2/3 Current attack pattern: • Initial access via unpatched CVEs (including CVE-2023-29357 & CVE-2023-24955) • Custom web shells dropped in sensitive directories (/_layouts/, /_catalogs/, /_vti_bin/) • Privilege escalation using SharePoint service accounts • Lateral movement + ransomware deployment via scheduled tasks or Group Policy • Heavy targeting of healthcare, finance, legal, and government environments Many organizations still run exposed SharePoint 2016/2019/Subscription Edition instances.
Post summary
The message outlines ongoing attacks exploiting unpatched SharePoint CVEs in targeted sectors, with no PoC, patch, or detailed vulnerability info provided.

