Schneier on Security

Subscribe to Schneier on Security feed
2025-11-15T09:49:00Z
Updated: 3 hours 44 min ago

Microsoft SharePoint Zero-Day

Mon, 07/28/2025 - 7:09am

Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to steal data worldwide:

The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the vulnerability, which affects SharePoint Servers that infrastructure customers run in-house. Microsoft’s cloud-hosted SharePoint Online and Microsoft 365 are not affected.

Here’s...

Pages