LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

sharepoint news

8 stories
ransomwarehigh

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water…

ransomwarehigh

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.

CVE-2026-63520critical

Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)

A remote code execution (RCE) vulnerability, identified as CVE-2026-63520, has been disclosed in Microsoft SharePoint, allowing an authenticated attacker to execute arbitrary code on a vulnerable server. When chained with an authentication bypass vulnerability, CVE-2026-55040, the exploit becomes unauthenticated.

CVE-2026-55040critical

SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit

Attackers have begun exploiting a critical authentication bypass vulnerability in Microsoft SharePoint, designated CVE-2026-55040, following the public release of a proof-of-concept (PoC) exploit. The flaw, which carries a CVSS score of 9.1, allows unauthenticated attackers to impersonate any SharePoint user, including administrators.

CVE-2026-55040critical

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability, identified as CVE-2026-55040, according to recent reports. This exploitation campaign began shortly after a proof-of-concept (PoC) exploit for the flaw was publicly released. The vulnerability is described as a security feature bypass, enabling unauthenticated attackers to impersonate legitimate users within…

CVE-2026-25089critical

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to address them by July 19, 2026. The newly listed flaws include one affecting Microsoft SharePoint and two impacting Fortinet FortiSandbox products.

CVE-2026-58644critical

Microsoft SharePoint Server RCE Vulnerability Exploited in the Wild

Microsoft has confirmed active exploitation of a critical remote code execution (RCE) vulnerability, CVE-2026-58644, affecting on-premises deployments of its SharePoint Server. The vulnerability, which stems from the deserialization of untrusted data (CWE-502), allows an unauthenticated attacker to execute arbitrary code with a CVSS v3.1 score of 9.8 (Critical).

helixhigh

New Helix Group Targets SharePoint Data via Vishing and MFA Abuse

A new data extortion group, dubbed Helix, has emerged, employing voice phishing (vishing) and multi-factor authentication (MFA) abuse to compromise SharePoint environments and exfiltrate data. The group's primary objective is to extort victim organizations by threatening to publish stolen information or sell it to other cybercriminals.