Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Best smart speakers & displays: 12 top picks for smart homes

    No DVD drive in your laptop? This USB add-on is only $20 right now

    A Dell-icious Chromebook too affordable to pass up — Only $200

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      AI models may be accidentally (and secretly) learning each other’s bad behaviors

      July 30, 2025

      Another Chinese AI model is turning heads

      July 15, 2025

      AI chatbot Grok issues apology for antisemitic posts

      July 13, 2025

      Apple sued by shareholders for allegedly overstating AI progress

      June 22, 2025

      How far will AI go to defend its own survival?

      June 2, 2025
    • Business

      Cloudflare open-sources Orange Meets with End-to-End encryption

      June 29, 2025

      Google links massive cloud outage to API management issue

      June 13, 2025

      The EU challenges Google and Cloudflare with its very own DNS resolver that can filter dangerous traffic

      June 11, 2025

      These two Ivanti bugs are allowing hackers to target cloud instances

      May 21, 2025

      How cloud and AI transform and improve customer experiences

      May 10, 2025
    • Crypto

      XRP Utility Under Fire in Viral Social Media Debate With Ripple CTO

      August 1, 2025

      Why PENGU’s Liquidation Heatmap Could Drive a Short-Term Rally

      August 1, 2025

      All You Need to Know about Hong Kong’s Stablecoin Day One

      August 1, 2025

      Stellar Faces Increasing Outflows – Is XLM Price at Risk?

      August 1, 2025

      What to Expect from Hedera (HBAR) Price in August 2025

      August 1, 2025
    • Technology

      Best smart speakers & displays: 12 top picks for smart homes

      August 1, 2025

      No DVD drive in your laptop? This USB add-on is only $20 right now

      August 1, 2025

      A Dell-icious Chromebook too affordable to pass up — Only $200

      August 1, 2025

      World’s first ultra-fast PCIe 6.0 SSD arrives, but it’s not for you

      August 1, 2025

      Nielsen’s RealEyes partnership offers an outcomes measurement solution

      August 1, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»SharePoint-ageddon attacks riddled with free Warlock ransomware
    Technology

    SharePoint-ageddon attacks riddled with free Warlock ransomware

    TechAiVerseBy TechAiVerseJuly 31, 2025No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    SharePoint-ageddon attacks riddled with free Warlock ransomware
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    BMI Calculator – Check your Body Mass Index for free!

    SharePoint-ageddon attacks riddled with free Warlock ransomware – and thousands of services could be compromised

    (Image credit: Future)

    • A remote code bug in SharePoint lets hackers hijack systems without even logging in
    • Storm-2603 is exploiting unpatched servers using chained bugs to gain long-term access undetected
    • ToolShell scored a perfect 10 on Bitsight’s risk scale, triggering immediate federal concern

    A critical flaw in on-premises Microsoft SharePoint Servers has escalated into a wider cybersecurity crisis, as attackers move from espionage to extortion.

    The campaign, initially traced to a vulnerability that allowed stealthy access, is now distributing ransomware, a development that adds an alarming layer of disruption to what was previously understood as a data-focused intrusion.

    Microsoft has linked this pivot to a threat actor it refers to as “Storm-2603,” and victims whose systems have been locked out must pay a ransom, typically in cryptocurrency.

    From silent access to full-blown extortion

    At the heart of the compromise are two severe vulnerabilities, which are CVE-2025-53770, dubbed “ToolShell,” and its variant CVE-2025-53771.

    These flaws allow unauthenticated remote code execution, giving attackers control over unpatched systems simply by sending a crafted request.

    The absence of login requirements makes these exploits particularly dangerous for organizations that have delayed applying security updates.

    Experts from Bitsight claim CVE-2025-53770 scores the maximum 10 on its Dynamic Vulnerability Exploit (DVE) scale, highlighting the urgency of remediation.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Security firms have noted a sharp uptick in attacks. Eye Security, which first reported signs of compromise, estimated 400 confirmed victims, up from 100 over the weekend, and warned the actual number is likely far higher.

    “There are many more, because not all attack vectors have left artifacts that we could scan for,” said Vaisha Bernard, chief hacker for Eye Security.

    US government agencies, including the NIH and reportedly the Department of Homeland Security (DHS), have also been affected.

    In response, CISA, DHS’s cyberdefense arm, has added CVE-2025-53770 to its Known Exploited Vulnerabilities list, mandating immediate action across federal systems once patches are released.

    One strain in circulation is said to be the “Warlock” ransomware, distributed freely within compromised environments.

    The pattern of chained exploits, combining the newer CVEs with older ones like CVE-2025-49704, points to a deeper structural issue in the security of on-premises SharePoint instances.

    Attackers have reportedly managed to bypass multi-factor authentication, steal machine keys, and maintain persistent access across affected networks.

    While SharePoint Online in Microsoft 365 remains unaffected, the impact on traditional server deployments has been widespread.

    Researchers estimate over 75 to 85 servers globally have already been compromised, with affected sectors spanning government, finance, healthcare, education, telecom, and energy.

    Globally, up to 9,000 exposed services remain at risk if left unpatched.

    Organizations are strongly urged to install the latest updates, KB5002768 for Subscription Edition, KB5002754 for SharePoint 2019, and KB5002760 for SharePoint 2016.

    Microsoft also recommends rotating MachineKey values post-patching and enabling AMSI (Antimalware Scan Interface) integration with Defender Antivirus.

    Additional guidance includes scanning for signs of compromise, such as the presence of spinstall0.aspx web shells, and monitoring logs for unusual lateral movement.

    Also, some organizations are now exploring ZTNA and Business VPN models to isolate critical systems and segment access.

    However, these measures are only effective if combined with strong endpoint protection and timely patch management.

    Via Reuters

    You might also like

    • These are the fastest SSDs you can buy right now
    • Take a look at some of the best external hard drives available
    • Semiconductor industry is losing billions of dollars ever year because of this quirk

    Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master’s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity. Upon joining TechRadar Pro, in addition to privacy and technology policy, he is also focused on B2B security products. Efosa can be contacted at this email: udinmwenefosa@gmail.com

    BMI Calculator – Check your Body Mass Index for free!

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleApple TV+ Snoopy Presents: A Summer Musical does something I’ve never seen in a Peanuts animated special, and even the trailer gave me chills
    Next Article United just opened its biggest-ever airport lounge, and it’s a dream for tech fans – here’s what’s inside
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Best smart speakers & displays: 12 top picks for smart homes

    August 1, 2025

    No DVD drive in your laptop? This USB add-on is only $20 right now

    August 1, 2025

    A Dell-icious Chromebook too affordable to pass up — Only $200

    August 1, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 202536 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202533 Views

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202529 Views

    OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits

    April 19, 202522 Views
    Don't Miss
    Technology August 1, 2025

    Best smart speakers & displays: 12 top picks for smart homes

    Best smart speakers & displays: 12 top picks for smart homes Image: Rob Schultz /…

    No DVD drive in your laptop? This USB add-on is only $20 right now

    A Dell-icious Chromebook too affordable to pass up — Only $200

    World’s first ultra-fast PCIe 6.0 SSD arrives, but it’s not for you

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Best smart speakers & displays: 12 top picks for smart homes

    August 1, 20252 Views

    No DVD drive in your laptop? This USB add-on is only $20 right now

    August 1, 20252 Views

    A Dell-icious Chromebook too affordable to pass up — Only $200

    August 1, 20252 Views
    Most Popular

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    French Apex Legends voice cast refuses contracts over “unacceptable” AI clause

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.