Visualização de leitura

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators.

Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, within days of Rapid7 releasing a public proof-of-concept on August 12. The vulnerability allows an unauthenticated attacker impersonate any SharePoint user or administrator without valid credentials. Microsoft patched it in July’s Patch Tuesday, anyone who hasn’t applied that update is directly exposed.

CVE-2026-55040 is a critical SharePoint authentication bypass. An unauthenticated attacker can exploit weaknesses in JWT validation to forge tokens and impersonate any SharePoint user, including administrators.

“A critical authentication bypass vulnerability exists in SharePoint Server Subscription Edition’s JWT token validation pipeline. The root cause is a chain of four distinct weaknesses that, when combined, allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user.” wrote Rapid7.

The exploit chain works by sending a JWT with “alg: none” in the outer header so no signature is required, using SharePoint’s own STS certificate thumbprint to resolve a signing key without verification, and then passing a non-empty but never-verified signature like “AAAA.” The result is a fully forged token that SharePoint accepts as legitimate.

Defused researchers observed attackers using the Rapid7 POC for CVE-2026-55040 against our SharePoint their honeypots.

🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots

The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday.

Track it live 👉pic.twitter.com/Q8fbMyGq95

— Defused (@DefusedCyber) August 12, 2026

Rapid7’s Python-based PoC, available on GitHub, uses the forged JWT token to query the target’s domain controller, enumerate users by SID, and automatically locate a site administrator. That last step matters because getting administrator-level access to SharePoint means access to documents, the ability to modify data, and a potential foothold into broader Microsoft 365 infrastructure. Microsoft’s advisory notes the attacker can’t disrupt availability, but reading files and modifying data across a SharePoint farm is damaging enough on its own.

The Hacker News reported that KEVIntel recorded 12 exploitation attempts since July 19, with eight occurring on August 12–13 after the public PoC release. The activity came from eight IP addresses across Hong Kong, Japan, the Netherlands, Taiwan and the U.S.

The spike immediately after the PoC publication confirms the pattern that repeats with nearly every high-severity vulnerability: public exploit code collapses the window between patch availability and active exploitation. Who’s behind these attempts and what they’re after remains unknown.

If your SharePoint instances haven’t received the July 2026 Patch Tuesday update, that’s the immediate action.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2026-55040)

SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue.

Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown attackers are believed to have exploited vulnerabilities in Microsoft’s SharePoint software. The software manufacturer had reported several such vulnerabilities in mid-July.

The FOITT is the largest IT service provider in the Federal Administration. It provides around 50,000 workstation systems, develops customised, secure and user-friendly IT solutions together with the administrative units, and operates over 1,000 specialist applications, mainly in its own modern data centres.

The FOITT operated the servers in the federal government’s own data centres and, according to its own statements, had immediately begun installing the security updates provided. FOITT detected the anomalies on July 28 and confirmed the account compromise three days later, on July 31.

“The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said.

“During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised.” reports the media outlet Swiss Info. “According to its own statements, the FOITT immediately reset the relevant passwords. Based on the investigations to date, which are being supported by the National Cybersecurity Centre (NCSC) and Microsoft, there is no evidence of any further data leakage. However, the analysis is still ongoing.”

Both user and technical accounts were hit. On the same day anomalous access was detected, FOITT blocked external internet access to SharePoint and began patching. It’s now reinstalling the affected servers entirely as a precaution and has shared all relevant technical indicators with Swiss critical infrastructure operators through the national cybersecurity agency’s platform.

The July Patch Tuesday timing matters here. Microsoft disclosed multiple serious SharePoint vulnerabilities on July 14. One flaw, tracked as CVE-2026-50522 (CVSS score of 9.8) could enable an attacker to execute remote code over a network. Microsoft said exploitation would be considered low complexity, as an attacker does not require a great deal of knowledge of the system to complete an attack. Researchers warned that attackers are stealing machine keys to maintain long-term access. That last part is the critical detail: machine keys are the cryptographic secrets that IIS uses to sign session tokens, and once stolen they let an attacker forge legitimate-looking requests that a fully patched server will still accept.

The Swiss FOITT is reinstalling the affected SharePoint servers as a precaution after the cyber incident. External internet access remains blocked until the work is complete, while federal employees can still access and share documents through alternative channels. FOITT pointed out that the platform is not intended to store confidential information or highly sensitive personal data.

Patching closes the door; it doesn’t change the locks. SharePoint is increasingly targeted by cybercriminals and nation-state actors because of its deep integration with Microsoft authentication. Attackers exploiting vulnerabilities could use it as an entry point to compromise wider networks, making direct internet exposure of SharePoint servers a growing security risk.

“CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances.” CERT-EU’s advisory warns. “Given the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.”

Neither Microsoft nor CISA have attributed the exploitations publicly to any specific threat group.

Switzerland’s National Cyber Security Centre (NCSC) recorded 28 cyberattacks targeting the Federal Administration in 2025 and 325 incidents affecting critical infrastructure, with about one in four involving public administration. One of the most notable cases hit the state-owned defense contractor Ruag, whose U.S. subsidiary was breached by the Akira ransomware group, leading to data theft and a ransom payment to recover the stolen information.

The practical takeaway for any organization still running on-premises SharePoint exposed to the internet: apply the July patches, then rotate your machine keys and restart IISm in that order, not one without the other. If you can’t take the server offline to reinstall it the way FOITT is doing, at minimum validate that external internet exposure has been eliminated. The window between vulnerability disclosure and active exploitation in this campaign was measured in days, not weeks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the flaws added to the KeV catalog:

  • CVE-2026-16232 (CVSS score of 9.3) Check Point SmartConsole Improper Authentication Vulnerability
  • CVE-2026-50522 (CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

The first flaw added to the KeV catalog is a critical authentication bypass flaw, tracked as CVE-2026-16232, affecting Security Management and Multi-Domain Management (MDSM).

The vulnerability, which is under active exploitation, allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access.

“An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.” reads the advisory. “Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”

Successful exploitation requires the Management Server to be accessible from the internet and Trusted Clients (GUI client) access restrictions to be disabled.

Check Point said it is aware of a limited number of customers targeted through CVE-2026-16232 and has already notified the affected organizations. The following attacker IP addresses have been identified as indicators of compromise (IoCs):

  • 151.241.99[.]207
  • 151.241.99[.]233
  • 158.62.198[.]182
  • 192.142.10[.]99
  • 139.28.37[.]250
  • 194.213.18[.]137

The flaw impacts the following products and versions:

  • Products: Security Management Server, Multi-Domain Security Management Server (MDS)
  • Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10

The second issue added to the catalog is a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522, that is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.

Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.

CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.

Organizations should apply the available security updates immediately.

watchTowr observed active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers shortly after public exploit code was released. Attackers are using the flaw to steal SharePoint machine keys in a single request, enabling persistent access even after patching. Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.

“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability. Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.” watchTowr wrote on LinkedIn. “Attackers are pulling SharePoint machine keys via a single request. Patching is not enough, defenders should rotate credentials on any assets that may have been exposed.”

Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint. The observed attacks require no authentication, consistent with the vulnerability’s unauthenticated remote code execution profile.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix these flaws by July 25, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code.

A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.

Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.

CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.

Organizations should apply the available security updates immediately.

watchTowr observed active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers shortly after public exploit code was released. Attackers are using the flaw to steal SharePoint machine keys in a single request, enabling persistent access even after patching. Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.

“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability. Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.” watchTowr wrote on LinkedIn. “Attackers are pulling SharePoint machine keys via a single request. Patching is not enough, defenders should rotate credentials on any assets that may have been exposed.”

Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint. The observed attacks require no authentication, consistent with the vulnerability’s unauthenticated remote code execution profile.

🚨 Update to our Jul 17 SharePoint report: we now assess the undocumented deserialization vector on our honeypots as likely CVE-2026-50522.

The captured requests carry no authentication material, matching 50522's unauthenticated profile. Microsoft describes the paired… https://t.co/t2EXqemSPr

— Defused (@DefusedCyber) July 20, 2026

In early July, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog.

At the end of May, Microsoft released security updates to patch the high-severity SharePoint vulnerability CVE-2026-45659 that could allow remote code execution. The flaw does not require complex conditions for exploitation, making it a serious risk for unpatched systems. Organizations using Microsoft SharePoint should apply the updates as soon as possible.

The root cause is deserialization of untrusted data.

In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Microsoft SharePoint Server flaw, tracked as CVE-2026-32201, to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-32201 (CVSS score of 6.5) is a spoofing vulnerability in Microsoft SharePoint Server, likely related to cross-site scripting (XSS). While details are limited, it could allow attackers to view or modify exposed information. Microsoft has not disclosed how widespread exploitation is, but given the potential impact, organizations, especially those with internet-facing SharePoint servers—should prioritize testing and applying the patch quickly.

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another SharePoint issue, tracked as CVE-2026-20963, its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft)

U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog.

  • CVE-2026-25089 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability  
  • CVE-2026-39808 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability  
  • CVE-2026-58644 (CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

This week, Microsoft’s July 2026 Patch Tuesday addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction. The flaw stems from the deserialization of untrusted data.

“Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.” reads the advisory. “In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.”

Microsoft confirmed it is aware of active exploitation of this vulnerability.

The second issue added to the KeV catalog is an OS command injection flaw, tracked as CVE-2026-25089, in FortiSandbox products. The vulnerability could allow remote, unauthenticated attackers to send specially crafted HTTP requests and execute arbitrary commands on affected devices. Adham El Karn of Fortinet Product Security team discovered the vulnerability.

The last issue added to the catalog, tracked as CVE-2026-39808, is an OS command injection flaw.

“An Improper Neutralization of Special Elements used in an OS Command (‘OS command injection’) vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.” reads the advisory.

Cybersecurity firm Defused Cyber confirmed it’s seen active exploitation of this vulnerability within a 24-hour window.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to urgently fix these flaws by July 19, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

DHS Confirms Breach of Homeland Security Information Network

DHS confirmed a breach of the Homeland Security Information Network, an unclassified platform used for security and emergency coordination.

The post DHS Confirms Breach of Homeland Security Information Network appeared first on TechRepublic.

Critical SearchLeak Flaw in Microsoft 365 Copilot Exposed Sensitive Enterprise Data

SearchLeak vulnerability

A newly disclosed SearchLeak vulnerability in Microsoft 365 Copilot Enterprise exposed a critical pathway for attackers to steal sensitive organizational data through a specially crafted URL. The flaw chain, now tracked as CVE-2026-42824, was patched by Microsoft earlier this month and assigned a critical severity rating due to its potential impact. Security researchers at Varonis discovered the issue by combining three separate weaknesses that, on their own, posed limited risk. Together, however, they enabled attackers to silently extract emails, calendar information, SharePoint documents, OneDrive files, and other indexed enterprise content accessible through Microsoft 365 Copilot Enterprise.

How the SearchLeak Vulnerability Worked 

According to the researchers, the SearchLeak vulnerability combined an AI-specific flaw known as Parameter-to-Prompt Injection (P2P) with two traditional web security issues: an HTML rendering race condition and a server-side request forgery (SSRF) vulnerability involving Bing.  The first stage exploited the search function of Microsoft 365 Copilot Enterprise, where the "q" URL parameter was passed directly to Copilot as an executable prompt. Instead of being treated as a simple search query, attacker-controlled input could be interpreted as instructions.  Researchers demonstrated that a malicious URL could instruct Copilot to search a victim’s mailbox, retrieve email titles or other sensitive content, and embed the extracted data inside an image URL without requiring any user interaction beyond a click. 

Chaining Three Flaws into One Attack 

The second stage relied on an HTML rendering race condition. While Microsoft attempted to neutralize potentially dangerous HTML by wrapping responses inside code blocks, that protection occurred only after Copilot completed generating its response. During the streaming phase, raw HTML, including image tags, could briefly render and trigger outbound requests before sanitization took effect.  The final component of the SearchLeak vulnerability involved a Content Security Policy bypass through Bing. Since Bing domains were allowlisted, attackers leveraged Bing’s image search endpoint, which performs server-side fetching of image URLs. By embedding stolen data within those URLs, Bing unknowingly acted as a proxy, forwarding the information to attacker-controlled servers.  As described by Varonis, the attack required no plugins, elevated privileges, additional clicks, or suspicious domains. Victims only needed to open a trusted Microsoft link. 

Potential Impact of CVE-2026-42824 

Because Microsoft 365 Copilot Enterprise operates with the user's existing permissions, successful exploitation of CVE-2026-42824 effectively granted attackers access to whatever information the targeted employee could access.  Potentially exposed data included email content, one-time passwords, password reset links, calendar events, meeting notes, attendee information, confidential communications, SharePoint files, OneDrive documents, earnings reports, salary information, acquisition plans, and other sensitive business records.  The researchers noted that the novelty of the SearchLeak vulnerability lies in how AI-enabled prompt injection made older attack techniques practical in a new environment. Without the P2P flaw, attackers could not inject malicious instructions; without the race condition, the HTML would be neutralized; and without the SSRF weakness, the Content Security Policy would block data exfiltration.  Microsoft has since remediated the issue under CVE-2026-42824, but researchers say the case highlights how AI systems can introduce new attack paths by connecting previously understood vulnerabilities in unexpected ways. 

Ransomware Tool Matrix Project Updates: Three Groups To Track

 


Introduction


This blog is a focused update on the latest updates to the Ransomware Tool Matrix (RTM) and the Ransomware Vulnerability Matrix (RVM) covering three groups that I have published profiles for to help defenders home in on the threats most relevant to them: TheGentlemen, DragonForce, and WarLock.


Rather than write another broad ecosystem summary, the goal of this post is to introduce these profiles, briefly explain why each group matters right now, and give readers direct links to them so defenders can pivot straight into hunting, detection engineering, and patch prioritisation.


For anyone new to the projects, please read the descriptions on GitHub or feel free to watch my talk explaining the project at BSides London.


Why these three groups?


Each of the three groups added in this update represents a different slice of the current ransomware ecosystem:


TheGentlemen


TheGentlemen is a newer operation that has matured quickly, with a large and varied toolkit that reflects how cross-pollinated the affiliate ecosystem has become. The recent internal chat leak gave researchers a rare look into their tradecraft, and the profiles capture both the tooling and the exploited CVEs that have been observed across multiple intrusions. TheGentlemen’s RTM profile is here and RVM profile is here.


DragonForce


DragonForce has continued to escalate throughout 2025 and into 2026, branching into MSP-focused attacks and standing up its own "cartel" model that other affiliates can plug into. Its exploitation of edge devices (Ivanti, Fortinet, SonicWall) and SimpleHelp RMM make it a high-priority threat for any organisation using such systems. DragonForce’s RTM profile is here and RVM profile is here.


WarLock


WarLock jumped onto everyone's radar after the ToolShell SharePoint zero-day exploitation campaign, and has since been linked to a string of edge-application exploits including SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack. It is a strong example of a likely China-based operator that lives on zero-day exploitation of internet-facing software. WarLock’s RTM profile is here and RVM profile is here.


Observations and Trends


A few themes are worth flagging across all three profiles:


  • BYOVD is now standard, not novel. All three groups have been observed bringing vulnerable drivers to disable or blind EDR. TheGentlemen with ThrottleStop driver, DragonForce with the TrueSight and Hangzhou Shunwang drivers, and WarLock with Antiy, NsecSoft, Rising, and VMTools drivers. If your detection stack is not yet hunting on or blocking suspicious driver loads and known-bad driver hashes, that is a high-priority gap to close.
  • Network edge devices and other internet-facing systems remain the front door to victim networks for these groups. Fortinet, Ivanti, SonicWall, SimpleHelp, Microsoft SharePoint, SmarterMail, SolarWinds Web Help Desk, and Gladinet CentreStack all appear across these three profiles. Patch prioritisation that focuses on internet-exposed appliances and admin tooling continues to give defenders a valuable return on effort.
  • Legitimate tooling continues to blur the line. Velociraptor, Cloudflared, VSCode Tunnels, AnyDesk, MeshCentral, FreeRDP, PuTTY, OpenSSH, and a long list of legitimate cloud services are all being repurposed for ransomware operations. Defender should use these lists to begin baselining what should exist in their environment and start alerting on the rest.

Conclusion


My recommendation for defenders remains the same as in previous updates: take the tools and CVEs from the RTM and RVM profiles and start threat hunting for their presence, writing detection rules to alert on certain behaviours, and blocking what is not expected or permitted in your environment. These three new profiles should make that easier to scope by group when you need to brief leadership, prioritise a hunt, or map your exposure to a specific campaign.


Here's a few sites that can help with turning the threat intel in these new profiles into detections:


- https://rulehound.com/rules

- https://detection.fyi

- https://www.snapattack.com/community


As always, feedback and pull requests are very welcome on both repos. Thanks to everyone who has contributed reports, corrections, and ideas. These projects only stay useful because the community keeps feeding them one way or another.

Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products

Overview On April 15, NSFOCUS CERT detected that Microsoft released the April Security Update patch, fixing 165 security issues involving Windows, Microsoft Office, Microsoft SQL Server, Microsoft Visual Studio, Microsoft .NET Framework, Widely used products such as Azure, including high-risk vulnerability types such as privilege escalation and remote code execution. Among the vulnerabilities fixed by […]

The post Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products appeared first on NSFOCUS.

The post Microsoft’s April Security Update of High-Risk Vulnerability Notice for Multiple Products appeared first on Security Boulevard.

CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability

Microsoft SharePoint, a core platform for enterprise collaboration, is facing active exploitation through a newly confirmed vulnerability, tracked as CVE-2026-20963. Rooted in unsafe deserialization of user-controlled data, this vulnerability allows remote.

The post CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability appeared first on Indusface.

The post CVE-2026-20963: SharePoint Deserialization Remote Code Execution Vulnerability appeared first on Security Boulevard.

Microsoft Patch Tuesday, November 2025 Edition

Microsoft this week pushed security updates to fix more than 60 vulnerabilities in its Windows operating systems and supported software, including at least one zero-day bug that is already being exploited. Microsoft also fixed a glitch that prevented some Windows 10 users from taking advantage of an extra year of security updates, which is nice because the zero-day flaw and other critical weaknesses affect all versions of Windows, including Windows 10.

Affected products this month include the Windows OS, Office, SharePoint, SQL Server, Visual Studio, GitHub Copilot, and Azure Monitor Agent. The zero-day threat concerns a memory corruption bug deep in the Windows innards called CVE-2025-62215. Despite the flaw’s zero-day status, Microsoft has assigned it an “important” rating rather than critical, because exploiting it requires an attacker to already have access to the target’s device.

“These types of vulnerabilities are often exploited as part of a more complex attack chain,” said Johannes Ullrich, dean of research for the SANS Technology Institute. “However, exploiting this specific vulnerability is likely to be relatively straightforward, given the existence of prior similar vulnerabilities.”

Ben McCarthy, lead cybersecurity engineer at Immersive, called attention to CVE-2025-60274, a critical weakness in a core Windows graphic component (GDI+) that is used by a massive number of applications, including Microsoft Office, web servers processing images, and countless third-party applications.

“The patch for this should be an organization’s highest priority,” McCarthy said. “While Microsoft assesses this as ‘Exploitation Less Likely,’ a 9.8-rated flaw in a ubiquitous library like GDI+ is a critical risk.”

Microsoft patched a critical bug in OfficeCVE-2025-62199 — that can lead to remote code execution on a Windows system. Alex Vovk, CEO and co-founder of Action1, said this Office flaw is a high priority because it is low complexity, needs no privileges, and can be exploited just by viewing a booby-trapped message in the Preview Pane.

Many of the more concerning bugs addressed by Microsoft this month affect Windows 10, an operating system that Microsoft officially ceased supporting with patches last month. As that deadline rolled around, however, Microsoft began offering Windows 10 users an extra year of free updates, so long as they register their PC to an active Microsoft account.

Judging from the comments on last month’s Patch Tuesday post, that registration worked for a lot of Windows 10 users, but some readers reported the option for an extra year of updates was never offered. Nick Carroll, cyber incident response manager at Nightwing, notes that Microsoft has recently released an out-of-band update to address issues when trying to enroll in the Windows 10 Consumer Extended Security Update program.

“If you plan to participate in the program, make sure you update and install KB5071959 to address the enrollment issues,” Carroll said. “After that is installed, users should be able to install other updates such as today’s KB5068781 which is the latest update to Windows 10.”

Chris Goettl at Ivanti notes that in addition to Microsoft updates today, third-party updates from Adobe and Mozilla have already been released. Also, an update for Google Chrome is expected soon, which means Edge will also be in need of its own update.

The SANS Internet Storm Center has a clickable breakdown of each individual fix from Microsoft, indexed by severity and CVSS score. Enterprise Windows admins involved in testing patches before rolling them out should keep an eye on askwoody.com, which often has the skinny on any updates gone awry.

As always, please don’t neglect to back up your data (if not your entire system) at regular intervals, and feel free to sound off in the comments if you experience problems installing any of these fixes.

[Author’s note: This post was intended to appear on the homepage on Tuesday, Nov. 11. I’m still not sure how it happened, but somehow this story failed to publish that day. My apologies for the oversight.]

❌