ThreatCluster
  • Feed
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Microsoft SharePoint Hackers Switch Gears to Spread Ransomware

Threat Score:
63
TechRepublic Security
14 hours ago
Microsoft SharePoint Hackers Switch Gears to Spread Ransomware

Overview

Recent attacks targeting Microsoft SharePoint have escalated, with threat actors now deploying ransomware on vulnerable systems, according to Microsoft. This surge in malicious activity follows the release of multiple SharePoint security patches in July. Anupdate published to Microsoft’s blogreads, in part: “Expanded analysis and threat intelligence from our continued monitoring of exploitation activity by Storm-2603 leading to the deployment of Warlock ransomware.” Detailing the attack At least...

Continue Reading on Original Site

Related Articles

5 articles
1

Hackers Compromised Official Gaming Mouse Software to Deliver Windows-based Xred Malware

Cybersecurity News • 2 hours ago

Gaming peripheral manufacturer Endgame Gear has confirmed that hackers successfully compromised its official software distribution system, using the company’s OP1w 4K V2 mouse configuration tool to spread dangerous Xred malware to unsuspecting customers for nearly two weeks. The security breach, which occurred between June 26 and July 9, 2025, represents a troubling example of supply […]

Score
83
Read more
2

Microsoft Investigates Leak in Early Warning System Used by Chinese Hackers to Exploit SharePoint Vulnerabilities

GB Hackers • 2 hours ago

Microsoft Investigates Leak in Early Warning System Used by Chinese Hackers to Exploit SharePoint Vulnerabilities Chinese laws requiring vulnerability disclosure to the government create transparency issues and potential conflicts for international cybersecurity efforts. Microsoft is probing whether a leak from its confidential early warning system enabled Chinese state- hackers to exploit significant flaws in its SharePoint software, leading to breaches at over 400 organizations, including the

Score
74
Read more
3

Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities

Cybersecurity News • 4 hours ago

Microsoft Corp. is investigating whether a leak from its Microsoft Active Protections Program (MAPP) enabled Chinese state- hackers to exploit critical SharePoint vulnerabilities before patches were fully deployed, according to sources familiar with the matter. The investigation comes as cyber espionage attacks have compromised more than 400 organizations worldwide, including the U.S. National Nuclear Security […]

Score
71
Read more
4
Lab 1 report reveals unstructured data heightens breach risks

Lab 1 report reveals unstructured data heightens breach risks

Security Brief UK • 5 hours ago

Lab 1 report reveals unstructured data heightens breach risks Lab 1 has released a report that analyses 141 million files from 1,297 data breach incidents, highlighting significant risks of downstream fraud and cybercrime for organisations, employees and customers. The Anatomy of a Breach 2025 report offers an in-depth content-level investigation of breached datasets, focusing on the prevalence of unstructured files, such as financial documents, HR data, customer records and code files, that are

Score
71
Read more
5

2025-07-26 - Cluster AI Daily Threat Brief

ThreatCluster • 12 hours ago

# Daily Threat Intelligence Brief - July 26, 2025 ## Executive Summary Today's threat landscape remains dynamic and increasingly complex, with a notable rise in attacks targeting critical infrastructure and enterprise services. The most pressing threats stem from **phishing campaigns**, **ransomware attacks**, and **vulnerabilities in widely-used platforms** such as Microsoft SharePoint and AWS. With global ransomware incidents reportedly down 43% in the second quarter, the threat actors are r

Score
69
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

CVES
CVE-2025-49704
CVE-2025-49706
CVE-2025-53770
CVE-2025-53771
IP ADDRESSES
65.38.121.198
ATTACK TYPES
Phishing
Ransomware
COUNTRIES
Canada
China
Germany
VULNERABILITIES
RCE
COMPANIES
Microsoft
Okta
SECURITY VENDORS
Okta
PLATFORMS
Microsoft 365
SharePoint
Windows
APT GROUPS
APT27
APT31
RANSOMWARE
Defender
First
LockBit
Rapid
Storm
MITRE ATT&CK
Impersonation
Phishing
IP ADDRESSES
65.38.121.198
ARTICLE INFORMATION
Article #4928
Published 14 hours ago
TechRepublic Security