Sharepoint

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a…

3 days ago

PoC and Technical Details Released for SharePoint Remote Code Execution Vulnerability

Proof-of-concept (PoC) exploit code and deep technical details have now been released for CVE-2025-53770, a critical remote code execution (RCE)…

2 months ago

Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace

Threat actors are rapidly shifting their intrusion tradecraft toward high-speed, SaaS-centric attacks that completely bypass traditional endpoint security. Since October…

4 months ago

Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign

Microsoft Defender researchers have exposed a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting energy sector organizations through SharePoint file-sharing abuse. The…

7 months ago

CISA Warns of Chinese Hackers Exploiting SharePoint 0-Day Flaws in Active Exploitation

CISA has issued an urgent alert regarding active exploitation of critical Microsoft SharePoint vulnerabilities by suspected Chinese threat actors.  The…

1 year ago

Critical SharePoint RCE Vulnerability Exploited Using Malicious XML Payload Within Web Part

A newly disclosed remote code execution (RCE) vulnerability in Microsoft SharePoint has been identified, affecting the deserialization process of WebPart…

1 year ago

Microsoft Enhances Exchange & SharePoint Security With New Antimalware Scan

Microsoft has announced a significant security upgrade for Exchange Server and SharePoint Server through integration with the Windows Antimalware Scan…

1 year ago

Hackers Leveraging Microsoft Visio Files & SharePoint For Two-Step Phishing Attack

A new sophisticated phishing technique utilizes Microsoft Visio files and SharePoint in a two-step phishing attack. This two-step attack method…

2 years ago

QR Code Phishing Attack Bypasses Email Security Scanners & Abuse SharePoint

Quishing, or QR code phishing, is rapidly evolving as threat actors adapt their tactics to bypass email security scanners. By…

2 years ago

PoC Exploit Published For SharePoint XML eXternal Entity (XXE) Injection Vulnerability

A new XXE (XML eXternal Entity) Injection has been discovered to affect SharePoint on both on-prem and cloud instances. This…

2 years ago