What happened. In mid-July 2025, attackers chained two SharePoint zero-days (CVE-2025-53770/53771), rapidly compromising hundreds of orgs across government, healthcare, and finance. CISA added them to KEV and issued analysis, and Microsoft confirmed active...
The “ToolShell” Summer: SharePoint zero-days, real-world fallout, and Microsoft’s new rules
read more



