
🚨Warlockランサムウェアが引き続きToolShell悪用、重要インフラに攻撃を拡大(CVE-2025-49704、CVE-2025-49706) ⚠️GitLab、AIゲートウェイサービスにおける重大なRCEの脆弱性について警告:CVE-2026-90970 〜サイバーセキュリティ週末の話題〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47913/
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-23. Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Priority
HIGH
Exploitation
ACTIVE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
2 versions affected across 1 product
| Date | Total | Labels |
|---|
| 2026-02-20 | 1 | Active Exploitation1 |
| 2026-04-01 | 1 | General1 |
| 2026-04-03 | 1 | Patch1 |
| 2026-07-23 | 1 | Active Exploitation1 |
| 2026-09-25 | 1 | Disclosure1 |

🚨Warlockランサムウェアが引き続きToolShell悪用、重要インフラに攻撃を拡大(CVE-2025-49704、CVE-2025-49706) ⚠️GitLab、AIゲートウェイサービスにおける重大なRCEの脆弱性について警告:CVE-2026-90970 〜サイバーセキュリティ週末の話題〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47913/

Success! After hours of debugging, I found that removing runat="server" from the outer most element of the CVE-2025-49704 payload generated by YSoNet fixed it. Every in the wild sample I've seen has this field set so I'm pretty confused now. @irsdl any idea why this might be? https://t.co/ZMEl8qIBMu
Post summary
The user discovered that omitting the runat="server" attribute from the outermost element in the CVE‑2025‑49704 payload generated by YSoNet resolves the issue, noting that wild samples typically include this field and thus the vulnerability is actively exploited.

Has anyone managed to exploit any of the SharePoint ToolPane CVE's on a freshly installed server? I'm testing out a CVE-2025-49704 payload generated with http://YSo.NET against 16.0.10417.20018 in my lab and whilst the auth bypass works, the payloads fail to deserialise
Post summary
The post documents a test of CVE-2025-49704 on SharePoint, noting successful authentication bypass but payload deserialization failure, with no evidence of active exploitation or mitigation.

🚨 #ALERT — WARLOCK RANSOMWARE CAMPAIGN HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT October 1, 2026 DISCLOSED BY: Symantec / Carbon Black CONFIRMED EXPLOITED BY: Symantec / Carbon Black PRODUCT: Microsoft SharePoint Server — On-Premises CVE: Multiple SharePoint vulnerabilities are used across the campaign. Historically associated ToolShell flaws include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. IMPACT: Symantec documented a recent Warlock campaign compromising at least four organizations, including a water utility and telecommunications provider, plus a regional government body and university. In one critical-infrastructure intrusion, attackers disabled security tooling on at least 40 hosts in roughly two hours and deployed Warlock ransomware to at least 33 systems through the domain SYSVOL share. EXPLOITATION STATUS: CONFIRMED OPERATIONAL RANSOMWARE CAMPAIGN CISA records knownRansomwareCampaignUse: Known for the core ToolShell KEV entries CVE-2025-49704, CVE-2025-49706 and CVE-2025-53770. The exact SharePoint CVE used for every recent intrusion has NOT been established. Attribution: Symantec tracks the actor as Longlegs, also associated with Storm-2603, and assesses it as China-nexus. This is NOT a formal government attribution to the Chinese state. Forensic triage: Hunt for SharePoint LAYOUTS web shells, stolen http://ASP.NET machine keys, K7RKScan/BYOVD activity, Visual Studio Code tunnels, NetExec, suspicious SYSVOL payloads and domain-wide ransomware staging. URGENT ACTION: Patch all on-premises SharePoint servers. Previously exposed systems require compromise assessment, http://ASP.NET machine-key rotation, credential review, and hunting across SYSVOL and domain controllers; patching alone does not establish that the environment is clean. SOURCE: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json?utm_source=chatgpt.com CONFIDENCE: VERY HIGH for the campaign, victim scope and observed post-exploitation behavior based on direct Symantec/Carbon Black investigations. The China-nexus attribution is a vendor intelligence assessment, not a formal government attribution. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #ToolShell #Warlock #Storm2603 #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics

Microsoft DART investigated a ransomware breach of on-premises SharePoint servers where two separate threat actors were found operating simultaneously, exploiting CVE-2025-49706 and CVE-2025-49704. Key findings: - Storm-2603, assessed as China-based, exploited CVE-2025-49706 (SharePoint auth spoofing) and CVE-2025-49704 (SharePoint code injection) to gain initial access, then used Velociraptor at SYSTEM-level for recon, blending into trusted admin behavior. Remote access was maintained via Cloudflare tunneling, Zoho Assist, and SSH through Visual Studio Code, followed by new local and domain admin account creation. - A second, unidentified threat actor operated concurrently in the same environment using DLL sideloading into legitimate Windows processes and custom backdoors, neither linked to Storm-2603. The layered activity from two actors obscured each other, complicating attribution and timeline reconstruction. - The driver NSecKrnl.sys was loaded to tamper with memory and disable endpoint protections before subsequent activity, a classic BYOVD move that blind-spots EDR before the heavier tooling arrives. - DART confirmed at least two victim organizations through lateral movement forensics, and any unpatched internet-facing SharePoint server remains exposed. #DFIR_Radar
Post summary
Microsoft DART reports a ransomware attack on on‑premises SharePoint servers, demonstrating active exploitation of CVE-2025-49706 and CVE-2025-49704 with detailed attacker tactics and tools.

Yes, in 2025, Chinese state-linked hackers exploited Microsoft SharePoint flaws (CVE-2025-49704/49706) to breach US agencies like DHS and potentially defense systems. This could qualify as a foreign threat under IEEPA for sanctions or asset freezes, but not broad tariffs per SCOTUS. Sources: CISA, NYT. Is this tied to emergency powers?
Post summary
Chinese state-linked hackers actively exploited CVE‑2025‑49704/49706 in Microsoft SharePoint to breach U.S. agencies such as DHS in 2025, indicating real-world attacks.

Warlock/Longlegs is exploiting ToolShell SharePoint vulnerabilities—using CVE-2025-49704/49706 and bypasses CVE-2025-53770/53771—to breach critical infrastructure in Portuguese- and Spanish-speaking countries. From web shells to stolen machine keys, driver abuses to SYSVOL-based ransomware deployment, its tactics show patching alone isn’t enough against modern ransomware threats. #SharePoint #Ransomware #Warlock #ToolShell #Cybersecurity #CriticalInfrastructure https://thedailytechfeed.com/warlock-strikes-unpatched-sharepoint-servers-to-deploy-ransomware/

Warlock ransomware operators chained four SharePoint CVEs for domain access on July 22. Unspecified on-prem builds were hit with CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 via ToolShell. Microsoft linked the same chain to Linen Typhoon, Violet Typhoon, and Storm-2603. Within two hours the operators dropped an AV/EDR killer to 40 hosts via BYOVD. They abused the signed K7RKScan.sys driver through CVE-2025-1055 to load a malicious kernel module and disable protections, then deployed a multi-version SharePoint web shell for persistence. NetExec handled AD enumeration and spraying while VS Code Insiders ran as a service for tunneling. Ransomware binaries were staged in the domain SYSVOL share for GPO and logon script distribution. Artifacts were deleted two days later. Warlock executed on 33 hosts by July 31 against a water utility, telecom provider, regional government, and university in Portuguese- and Spanish-speaking regions. Symantec attributes the activity to Longlegs. BYOVD via K7RKScan plus SYSVOL staging turned SharePoint access into domain-wide execution in under ten days.

🚨 #ALERT — WARLOCK RANSOMWARE ACTORS CONTINUE EXPLOITING SHAREPOINT, HITTING WATER AND TELECOM OPERATORS October 1, 2026 DISCLOSED BY: Symantec / Broadcom Threat Hunter Team CONFIRMED EXPLOITED BY: Longlegs / Storm-2603 PRODUCT: Microsoft SharePoint Server — On-Premises CVE: No single CVE is publicly confirmed for every recent intrusion. Historically associated ToolShell chain: CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 IMPACT: SharePoint exploitation → web shell → http://ASP.NET Machine Key theft → code execution → lateral movement → AV/EDR disruption → domain-scale Warlock ransomware deployment. EXPLOITATION STATUS: CONFIRMED ACTIVE EXPLOITATION CONFIRMED RANSOMWARE DEPLOYMENT CRITICAL-INFRASTRUCTURE VICTIMS CONFIRMED Forensic triage: Hunt for SharePoint LAYOUTS web shells, Machine Key theft, new privileged accounts, VS Code Tunnel services, BYOVD activity and ransomware/SYSVOL staging. URGENT ACTION: Fully patch on-prem SharePoint. Rotate http://ASP.NET Machine Keys on exposed or suspected systems and restart IIS. Investigate previously vulnerable systems before treating them as clean. SOURCE: https://www.security.com/blog-post/warlock-ransomware-critical-infrastructure EXPLOITATION UPDATE: Symantec observed at least four recent victims: a water utility, telecom operator, regional government body and university across Europe, Africa and Latin America. In one intrusion, an AV/EDR-killing tool reached 40+ hosts and Warlock ransomware was deployed to at least 33 hosts using SYSVOL replication. SUPPORTING SOURCE: https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ CONFIDENCE: VERY HIGH — direct Symantec/Broadcom incident telemetry. HIGH — Longlegs/Storm-2603 attribution is consistent with prior Microsoft reporting. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #Warlock #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics #Storm2603

NØØT Security Alerts Classification: Critical CVE: CVE-2025-49704 Product: Microsoft / SharePoint Summary: VulnCheck reports real-world exploitation activity affecting Microsoft / SharePoint. Evidence: Ransomware use confirmed; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 18 Jul 2025 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Microsoft #SharePoint #CVE_2025_49704 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

Urgent warning: the Warlock ransomware group is exploiting serious SharePoint flaws (ToolShell chain, CVE-2025-49704/6, 53770/71) to compromise water, telecom, gov, and education sectors. Beyond patching, defenders need detection of webshells, machine-key rotation, EDR enforcement, limited internet exposure, and robust recovery plans to stop domain-wide damage. #Warlock #Ransomware #SharePoint #CyberSecurity #CriticalInfrastructure #ThreatIntel https://thedailytechfeed.com/warlock-ransomware-uses-sharepoint-flaws-to-hit-utilities-telecom/

🔴 #Microsoft SharePoint Code Injection Remote Code Execution, #CVE-2025-49704 (High) -DC-Sep2026-2584 https://dailycve.com/microsoft-sharepoint-code-injection-remote-code-execution-cve-2025-49704-high-dc-sep2026-2584/
Post summary
This tweet announces CVE-2025-49704, a high-severity code injection remote code execution flaw in Microsoft SharePoint, and links to a detail page. It provides technical classification details but does not mention exploits, patches, or active exploitation.
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | microsoft | sharepoint_server | 2016 | - | - |
| App | microsoft | sharepoint_server | 2019 | - | - |