CISA added a Microsoft SharePoint compromise template to its free Eviction Strategies Tool to help incident-response teams contain and remove attackers from compromised on-premises SharePoint servers. Built on Playbook-NG and the COUN7ER countermeasure database, the template maps relevant MITRE ATT&CK techniques to ten post-compromise actions that organizations can tailor for response playbooks, including critical-infrastructure operators such as water and wastewater utilities.
The guidance follows severe on-premises SharePoint Server flaws, including CVE-2025-53770 and CVE-2025-53771, which can enable unauthorized access to SharePoint, theft of sensitive information, and lateral movement into broader IT environments. Microsoft issued security updates, while the Dutch NCSC reported monitoring exploitation and notifying affected Dutch organizations; SharePoint Online in Microsoft 365 is not affected.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added an on-premises Microsoft SharePoint compromise template that maps relevant MITRE ATT&CK techniques to ten post-compromise countermeasures. The template can be customized and exported as part of an incident-response playbook.
CISA initially released its no-cost Eviction Strategies Tool, including Playbook-NG and the COUN7ER countermeasure database, to help organizations build customized adversary-eviction playbooks.
The Dutch NCSC found vulnerable SharePoint systems at multiple Dutch and foreign organizations and notified several Dutch organizations whose vulnerability had been exploited. It began monitoring possible exploitation and urged organizations to apply mitigations and inspect for compromise.
Microsoft released security updates for CVE-2025-53770 and CVE-2025-53771, severe flaws affecting on-premises SharePoint Server 2016, 2019, and Subscription Edition. SharePoint Online in Microsoft 365 was not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.