yousukezan[verified]@yousukezanPoC
A proof‑of‑concept exploit and detailed technical information for CVE‑2025‑53770, a SharePoint Server RCE due to a deserialization flaw, have been publicly released, increasing risk for unpatched systems but no evidence of active exploitation.
Team Cymru Research[verified]@teamcymru_S2Active Exploitation
The tweet identifies the top 25 CVEs that have seen the most exploitation attempts over a 14‑day period, indicating active use by threat actors.
Dwinity[verified]@dwinity_ecoPatch
The post highlights that patching alone does not mitigate CVE‑2025‑53770 because the stolen ASP.NET MachineKey stays valid, prompting Microsoft to advise rotating the key, and no exfiltration has been observed yet.
Gagan Suie[verified]@gagansuieActive Exploitation
Attackers are actively exploiting CVE‑2025‑53770 to pull ASP.NET machine keys from on‑prem SharePoint servers, demonstrating real‑world impact.
Cyber News Live[verified]@cybernewsliveActive Exploitation
The report highlights that a small subset of newly discovered vulnerabilities—CVE-2025-55182, CVE-2025-53770, and CVE-2025-31324—are being actively exploited by threat actors before patches are released.
Alex[verified]@xaitaxPatch
The text highlights a website that aggregates patch and technical details for CVE‑2025‑53770, emphasizing the availability of fixes but providing no proof‑of‑concept or active exploitation information.
Sir Will@cxsnrdActive Exploitation
The post confirms that CVE‑2025‑53770 was actively exploited before detection signatures existed, but no evidence of a PoC, exploit code, patch, or technical details is given.
TI Mindmap HUB@ti_mindmap_hubActive Exploitation
The post confirms that ransomware operators, notably UNC6357, are actively exploiting SharePoint CVE‑2025‑53770 to deploy LOCKBIT.WARLOCK, highlighting real‑world attacks without any mention of patches or workarounds.