#sharepoint


Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Oct 3, 2026 // 17:37

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations […]

Warlock ransomware breach SharePoint in water, telecom operator attacks

Oct 2, 2026 // 23:17

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain […]

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Sep 26, 2026 // 13:38

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities […]

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

Sep 25, 2026 // 20:37

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider […]

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Sep 22, 2026 // 14:22

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according […]

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Aug 27, 2026 // 19:40

A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into […]

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Aug 27, 2026 // 00:57

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat […]

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Aug 19, 2026 // 14:11

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being […]

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Aug 18, 2026 // 15:41

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. “TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its […]

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Aug 13, 2026 // 10:35

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is […]

1 2 3 Next