Microsoft disclosed multiple on-premises SharePoint Server vulnerabilities, including remote code execution flaws CVE-2025-49701 and CVE-2025-49704 and spoofing flaw CVE-2025-49706, as defenders responded to active exploitation. Microsoft said it was working to disrupt attacks targeting exposed SharePoint environments, while the Canadian Centre for Cyber Security issued threat-detection guidance to help organizations identify compromise tied to the SharePoint vulnerabilities.
Subsequent reporting tied the broader ToolShell exploitation chain, including CVE-2025-53770, to China-linked operators that breached a Middle Eastern telecom provider, government departments in Africa, government agencies in South America, and a U.S. university. Investigators said the intrusions used malware and tooling including Zingdoor, ShadowPad, KrustyLoader, and Sliver, alongside credential-dumping, proxying, DLL sideloading, and persistence techniques, indicating a stealthy espionage-focused campaign that expanded beyond initial public understanding of the SharePoint attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Symantec reported that ToolShell exploitation had compromised a Middle Eastern telecom, two African government departments, two South American government agencies, and a U.S. university, with likely additional victims in Africa, the Middle East, and Europe. The report also described tooling including Zingdoor, ShadowPad, KrustyLoader, Sliver, and credential-dumping utilities, and assessed the operators as China-based actors engaged in likely espionage.
The Canadian Centre for Cyber Security published threat detection guidance related to SharePoint vulnerabilities. This reflects official defensive guidance for organizations monitoring for related exploitation activity.
Microsoft published a security blog on disrupting active exploitation of on-premises SharePoint vulnerabilities. The post signaled that exploitation was ongoing and outlined Microsoft's response to the campaign.
CRN reported Mandiant's assessment that a China-based threat actor was involved in the Microsoft SharePoint attack activity. This represented an early public attribution update tying the exploitation to China-linked operators.
According to later Symantec reporting, China-linked attackers exploited the ToolShell SharePoint vulnerability CVE-2025-53770 soon after Microsoft patched SharePoint in July 2025. Early victims included a telecom company in the Middle East and government entities in Africa, indicating rapid post-patch operational use.
Microsoft released Security Update Guide entries for multiple on-premises SharePoint vulnerabilities, including remote code execution flaws CVE-2025-49701 and CVE-2025-49704 and spoofing flaw CVE-2025-49706. These July 8 advisories mark the initial public patch/disclosure point in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
security.com
Open sourcecyber.gc.ca
Open sourcemicrosoft.com
Open sourcecrn.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.