#sharepoint

25 posts · Last used 3d

Back to Timeline
Sass, David @sassdawe@infosec.exchange · 3d ago
Replying to @sassdawe@infosec.exchange
@puppygirlhornypost2@transfem.social @wdormann@infosec.exchange that said, if someone needs help patching #SharePoint Server and/or taking it off of the internet and making it accessible securely, so vulnerabilities like this won't require immediate servicing I am available to help.
0
0
0
Michael I Ransier @thecybermind@infosec.exchange · 3d ago
CRITICAL THREAT: CVE-2026-50522 in Microsoft SharePoint enables unauthenticated remote code execution via untrusted data deserialization. Active exploitation is confirmed! Get the forensic detection queries and hardening strategies needed to secure your infrastructure now. https://thecybermind.co/jttd #CyberSecurity #InfoSec #SharePoint #ThreatInte
0
0
0
heise Security @heisec@social.heise.de · 3d ago
Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert. https://www.heise.de/news/Microsoft-SharePoint-Angriffe-auf-weitere-Sicherheitsluecke-11374506.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon #Cyberangriff #Cybercrime #Exploit #IT #Microsoft #Security #SharePoint #Sicherheitslücken #Updates #news
0
0
1
Suriq - Always on Watch @suriq@infosec.exchange · 3d ago
Third on-prem SharePoint RCE this month: CVE-2026-50522 (CVSS 9.8) went from public PoC to active exploitation in hours. All three July flaws steal the server machine key. Patch, then ROTATE the key, or a patched box is still owned. #SharePoint #infosec https://suriq.io/blog/sharepoint-cve-2026-50522-rotate-machine-keys #CVE #Detection #CISAKEV #infosec
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · 3d ago
A third SharePoint vulnerability is now being actively exploited. CVE-2026-50522 (CVSS 9.8) is a critical .NET deserialization vulnerability affecting on-premises SharePoint Server. Following the release of a public PoC, researchers observed attackers exploiting the flaw to extract ASP.NET machine keys, enabling persistent access beyond simply achieving RCE. One important point: applying Microsoft's patch may not be sufficient if a server was already compromised. Incident response should include reviewing IIS logs, investigating potential machine key exposure, and rotating compromised cryptographic secrets where necessary. I published a technical deep dive covering everything. Read here: https://thecybersecguru.com/news/sharepoint-cve-2026-50522-active-exploitation/ #InfoSec #CyberSecurity #SharePoint #Microsoft #DFIR #ThreatHunting #BlueTeam #Vulnerability
0
0
0
Sass, David @sassdawe@infosec.exchange · 4d ago
Any #SharePoint Server operators left in #europe or everyone is on the cloud already?
0
0
0
Cloud 🤖 @cloud@infosec.exchange · 4d ago
🤖 CVE-2026-50522 (CVSS 9.8): Critical deserialization RCE in SharePoint Server exploited in the wild after watchTowr published a PoC. Apply the July 2026 Patch Tuesday update immediately. 🔗 https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html #CVE #RCE #SharePoint #CyberSec
0
0
0
Ben Schorr :donor: @bschorr@infosec.exchange · 5d ago
This one is interesting - we often recommend firms review their document retention policies to ensure they're accurate and enforced, in part to help #Copilot ground on the right material. This adds a helpful nuance, letting admins designate #SharePoint sites that are particularly valuable to give them extra priority in Copilot. https://deltapulse.app/item/503553
0
0
0
Michael I Ransier @thecybermind@infosec.exchange · 6d ago
⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. https://thecybermind.co/9pxn #CyberSecurity #InfoSec #SharePoint #CVE2026
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 17, 2026
🤖 CVE-2026-58644 (CVSS 9.8): Active exploitation of a critical deserialization RCE in Microsoft SharePoint Server. CISA added to KEV, federal agencies must patch by July 19. PoC expected soon. 🔗 https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html #CVE #RCE #SharePoint #CyberSec
0
0
0
OffSequence @offseq@infosec.exchange · Jul 17, 2026
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 17, 2026
CISA KEV catalog adds three actively exploited flaws: FortiSandbox CVE-2026-25089, CVE-2026-39808, and SharePoint CVE-2026-58644. Patch by July 19. #CISA #KEV #Fortinet #FortiSandbox #SharePoint #CVE202658644 #ActivelyExploited #CyberSecurity https://securityonline.info/cisa-kev-fortisandbox-sharepoint/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 15, 2026
🤖 CISA warns admins to patch actively exploited SharePoint flaws. Three vulnerabilities in on-premises SharePoint Server are being actively exploited. CISA added them to the KEV catalog — patch exposed instances immediately. 🔗 https://www.bleepingcomputer.com/news/security/cisa-warns-admins-to-patch-actively-exploited-sharepoint-flaws/ #CVE #SharePoint #CyberSec #Exploit
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 15, 2026
CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://securityonline.info/cisa-sharepoint-hardening/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 10, 2026
1
0
2
Ben Schorr :donor: @bschorr@infosec.exchange · Jul 11, 2026
I'm using the #Copilot chat in #SharePoint to build out SharePoint pages today and I have to say, it's really quite good. I've created half a dozen pages with pretty decent content and links and it's taken me less than 30 minutes so far.
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 03, 2026
🚨 Hackers breached a DHS information-sharing network used by federal, state, local, and private-sector partners. The incident reportedly impacted both HSIN and an associated SharePoint collaboration system, raising fresh concerns about securing legacy government infrastructure and sensitive operational data. What happened, what HSIN is, and why this breach matters👇 🔗 https://thecybersecguru.com/news/hsin-breach-dhs-sharepoint-hack/ #CyberSecurity #DataBreach #DHS #SharePoint #InfoSec #BlueTeam #ThreatIntel #GovTech #CyberNews
0
0
0