Csoonline Multiple Attackers Exploit Unpatched SharePoint Servers, Microsoft Reports
Article Content
- •Two distinct threat actors operated simultaneously within the same environment.
- •Storm-2603 exploited vulnerabilities in SharePoint servers to deploy ransomware.
- •A second unidentified actor used DLL sideloading and targeted Active Directory databases.
Microsoft's DART team discovered two distinct threat actors operating simultaneously within the same victim network, complicating incident response efforts. The investigation began with ransomware activity linked to Storm-2603, which exploited vulnerabilities in on-premises SharePoint servers. The attackers created unauthorized administrator accounts and disabled security controls using a vulnerable driver. Concurrently, a second unidentified actor employed DLL sideloading techniques and attempted to access Active Directory credential databases. This overlapping activity obscured the full scope of the intrusion, complicating the reconstruction of the attack timeline. Microsoft emphasized that such simultaneous intrusions are becoming more common, as they can mask each other's activities. The investigation revealed that both actors used different tools and objectives, highlighting the complexity of modern cyberattacks. The incident underscores the need for improved detection and response strategies to handle overlapping threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Klue and CVE-2025-11371 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…