home.social

#toolshell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #toolshell, aggregated by home.social.

fetched live
  1. Raport Cisco Talos: ransomware słabnie? Niekoniecznie, ale celuje teraz w urzędy

    Trzeci kwartał 2025 roku przyniósł istotną zmianę na mapie cyberzagrożeń. Choć udział ataków ransomware spadł, cyberprzestępcy obrali nowy, wyraźny cel: sektor publiczny.

    Według najnowszych danych Cisco Talos, to właśnie urzędy i instytucje samorządowe są teraz najbardziej narażone.

    Najnowszy raport Cisco Talos „Incident Response Trends Q3 2025” rzuca światło na taktyki hakerów. Choć odsetek incydentów z użyciem ransomware spadł z 50% (w Q2) do 20% (w Q3), eksperci ostrzegają przed optymizmem. Zagrożenie nie znika, a jedynie ewoluuje i staje się bardziej precyzyjne.

    Sektor publiczny na celowniku

    Po raz pierwszy w historii analiz Talos (od 2021 r.), organizacje rządowe i samorządowe znalazły się na szczycie listy celów. Hakerzy, w tym grupy powiązane z Rosją (APT), celują w szkoły, szpitale i lokalne urzędy. Dlaczego? Często dysponują one ograniczonym budżetem na IT i przestarzałą infrastrukturą, co czyni je łatwym łupem.

    Luki w aplikacjach to otwarta brama

    Aż 60% wszystkich incydentów w minionym kwartale rozpoczęło się od wykorzystania luk w publicznie dostępnych aplikacjach. To gigantyczny skok (wcześniej było to poniżej 10%).

    Głównym winowajcą okazały się ataki na lokalne serwery Microsoft SharePoint z wykorzystaniem łańcucha ataku ToolShell. Hakerzy działają błyskawicznie – pierwsze ataki odnotowano zaledwie dzień przed oficjalnym ostrzeżeniem Microsoftu o luce.

    „Cyberprzestępcy automatycznie skanują sieć w poszukiwaniu podatnych hostów, podczas gdy zespoły bezpieczeństwa walczą o czas (…) W tym kwartale ok. 15% incydentów dotyczyło infrastruktury pozbawionej aktualnych poprawek” – komentuje Lexi DiScola z Cisco Talos.

    MFA to za mało

    Raport przynosi też niepokojące wieści dla firm polegających na uwierzytelnianiu wieloskładnikowym (MFA). Prawie jedna trzecia incydentów wiązała się z obejściem lub nadużyciem tego zabezpieczenia.

    Przestępcy stosują technikę „MFA bombing” (zalewanie użytkownika powiadomieniami, aż ten dla świętego spokoju zaakceptuje logowanie) lub wykorzystują błędy w konfiguracji.

    Jak się bronić?

    Cisco Talos rekomenduje cztery kluczowe działania:

    • Błyskawiczne wdrażanie poprawek bezpieczeństwa (szczególnie dla aplikacji wystawionych do sieci).
    • Silną segmentację sieci (aby infekcja jednego serwera nie położyła całej firmy).
    • Wzmocnienie zasad MFA i monitorowanie prób logowania.
    • Pełną analizę logów bezpieczeństwa.

    Raport Cisco: 85% polskich firm chce agentów AI. Tylko 5% jest na nie gotowych

    #atakiHakerskie #ciscoTalos #cyberbezpieczenstwo #mfa #microsoftSharepoint #news #ransomware #raportBezpieczenstwa #sektorPubliczny #toolshell

  2. Raport Cisco Talos: ransomware słabnie? Niekoniecznie, ale celuje teraz w urzędy

    Trzeci kwartał 2025 roku przyniósł istotną zmianę na mapie cyberzagrożeń. Choć udział ataków ransomware spadł, cyberprzestępcy obrali nowy, wyraźny cel: sektor publiczny.

    Według najnowszych danych Cisco Talos, to właśnie urzędy i instytucje samorządowe są teraz najbardziej narażone.

    Najnowszy raport Cisco Talos „Incident Response Trends Q3 2025” rzuca światło na taktyki hakerów. Choć odsetek incydentów z użyciem ransomware spadł z 50% (w Q2) do 20% (w Q3), eksperci ostrzegają przed optymizmem. Zagrożenie nie znika, a jedynie ewoluuje i staje się bardziej precyzyjne.

    Sektor publiczny na celowniku

    Po raz pierwszy w historii analiz Talos (od 2021 r.), organizacje rządowe i samorządowe znalazły się na szczycie listy celów. Hakerzy, w tym grupy powiązane z Rosją (APT), celują w szkoły, szpitale i lokalne urzędy. Dlaczego? Często dysponują one ograniczonym budżetem na IT i przestarzałą infrastrukturą, co czyni je łatwym łupem.

    Luki w aplikacjach to otwarta brama

    Aż 60% wszystkich incydentów w minionym kwartale rozpoczęło się od wykorzystania luk w publicznie dostępnych aplikacjach. To gigantyczny skok (wcześniej było to poniżej 10%).

    Głównym winowajcą okazały się ataki na lokalne serwery Microsoft SharePoint z wykorzystaniem łańcucha ataku ToolShell. Hakerzy działają błyskawicznie – pierwsze ataki odnotowano zaledwie dzień przed oficjalnym ostrzeżeniem Microsoftu o luce.

    „Cyberprzestępcy automatycznie skanują sieć w poszukiwaniu podatnych hostów, podczas gdy zespoły bezpieczeństwa walczą o czas (…) W tym kwartale ok. 15% incydentów dotyczyło infrastruktury pozbawionej aktualnych poprawek” – komentuje Lexi DiScola z Cisco Talos.

    MFA to za mało

    Raport przynosi też niepokojące wieści dla firm polegających na uwierzytelnianiu wieloskładnikowym (MFA). Prawie jedna trzecia incydentów wiązała się z obejściem lub nadużyciem tego zabezpieczenia.

    Przestępcy stosują technikę „MFA bombing” (zalewanie użytkownika powiadomieniami, aż ten dla świętego spokoju zaakceptuje logowanie) lub wykorzystują błędy w konfiguracji.

    Jak się bronić?

    Cisco Talos rekomenduje cztery kluczowe działania:

    • Błyskawiczne wdrażanie poprawek bezpieczeństwa (szczególnie dla aplikacji wystawionych do sieci).
    • Silną segmentację sieci (aby infekcja jednego serwera nie położyła całej firmy).
    • Wzmocnienie zasad MFA i monitorowanie prób logowania.
    • Pełną analizę logów bezpieczeństwa.

    Raport Cisco: 85% polskich firm chce agentów AI. Tylko 5% jest na nie gotowych

    #atakiHakerskie #ciscoTalos #cyberbezpieczenstwo #mfa #microsoftSharepoint #news #ransomware #raportBezpieczenstwa #sektorPubliczny #toolshell

  3. A single SharePoint flaw unleashed a global cyber takeover—hackers are seizing control even before patches hit. How safe is your system? Dive into the details of the ToolShell vulnerability.

    thedefendopsdiaries.com/the-to

    #toolshell
    #sharepoint
    #zeroday
    #cyberattacks
    #cve202553770

  4. A single SharePoint flaw unleashed a global cyber takeover—hackers are seizing control even before patches hit. How safe is your system? Dive into the details of the ToolShell vulnerability.

    thedefendopsdiaries.com/the-to

    #toolshell
    #sharepoint
    #zeroday
    #cyberattacks
    #cve202553770

  5. 🚨 New immediate detection live in Network Scanner 👉 #ToolShell (CVE-2025-53770) 🚨

    The latest update helps you confirm protection against ToolShell (CVE-2025-53770, CVSS 9.8) on SharePoint servers:

    ✅ Run instant, single-CVE scans on your SharePoint servers
    ✅ Verify if your patches actually worked
    ✅ Get clear, evidence-backed results for faster reporting and remediation

    Act on it right now with these resources 👇

    🔴 CVE details: pentest-tools.com/vulnerabilit

    👉 Use our Network Scanner for targeted detection: pentest-tools.com/network-vuln

    #vulnerabilityassessment #offensivesecurity #ethicalhacking

  6. 🚨 New immediate detection live in Network Scanner 👉 #ToolShell (CVE-2025-53770) 🚨

    The latest update helps you confirm protection against ToolShell (CVE-2025-53770, CVSS 9.8) on SharePoint servers:

    ✅ Run instant, single-CVE scans on your SharePoint servers
    ✅ Verify if your patches actually worked
    ✅ Get clear, evidence-backed results for faster reporting and remediation

    Act on it right now with these resources 👇

    🔴 CVE details: pentest-tools.com/vulnerabilit

    👉 Use our Network Scanner for targeted detection: pentest-tools.com/network-vuln

    #vulnerabilityassessment #offensivesecurity #ethicalhacking

  7. Kaspersky hat die durch ToolShell ausgenutzten Schwachstellen in Microsofts on-premise SharePont-Server intensiver aufgearbeitet.
    Da bleibst staunend zurück.
    securelist.com/toolshell-expla
    #infosec #microsoft #toolshell #sharepoint #BeDiS #kaspersky #securelist

  8. 🚨 SharePoint Zero-Day: Escalation Alert 🚨

    CVE-2025-53770 (“ToolShell”) is no longer a targeted attack — it’s a global campaign.

    Check Point Research now confirms:
    📈 4,600+ exploitation attempts
    🏢 300+ orgs targeted
    🌍 Expanding beyond the U.S. into UK, Italy, France & more
    🏦 New sectors in the crosshairs: financial services, business services & consumer goods

    If your organization has been impacted or you're looking to strengthen your defenses, we are here to help!

    🤝Let’s work together to protect what matters most: blog.checkpoint.com/research/s

    #CVE #cybersecurity #Toolshell

  9. Microsoft said the Chinese hackers are using the Warlock ransomware as part of the #ToolShell campaign

    therecord.media/microsoft-says

    Federal agencies confirmed to suffer incidents include
    - Dept. of Energy's National Nuclear Security Administration
    - Dept. of HHS's National Institutes of Health

    DHS declined to confirm NextGov reporting of a breach but said "there is no evidence of data exfiltration at DHS or any of its components at this time"

    EPA said they are not affected. State Department said it is investigating. No other agencies responded to requests for comment.

  10. Microsoft said the Chinese hackers are using the Warlock ransomware as part of the #ToolShell campaign

    therecord.media/microsoft-says

    Federal agencies confirmed to suffer incidents include
    - Dept. of Energy's National Nuclear Security Administration
    - Dept. of HHS's National Institutes of Health

    DHS declined to confirm NextGov reporting of a breach but said "there is no evidence of data exfiltration at DHS or any of its components at this time"

    EPA said they are not affected. State Department said it is investigating. No other agencies responded to requests for comment.

  11. From Check Point Research:

    Following Microsoft disclosure of a critical SharePoint 0-day vulnerability dubbed “ToolShell” (CVE-2025-53770, a variant of the authentication-bypass bug CVE-2025-49706), Check Point Research released an advisory with key findings on the vulnerability.

    blog.checkpoint.com/research/s

    #zeroday #toolshell #vulnerability #cve

  12. Patching SharePoint servers to make sure your infrastructure isn't vulnerable to #ToolShell (CVE-2025-53770) is half the job. The other half is validating that mitigations actually worked across your entire environment.

    Our Network Scanner provides immediate, targeted, and FAST detection for this 🔴 critical, unauthenticated RCE vulnerability:

    ✅ instantly scan your SharePoint servers with an effective, single-CVE scan
    ✅ quickly identify any remaining exposure to ToolShell, even after applying patches
    ✅ gain robust evidence (vulnerable endpoints, specific ports, validated findings) to confidently report on your security posture and prioritize remediation exactly where it's needed.

    Ready to act on it? Check out the resources below. 👇⬇️👇

    🔴 CVE details: pentest-tools.com/vulnerabilit

    👉 you can act on with our Network Scanner: pentest-tools.com/network-vuln "

  13. Patching SharePoint servers to make sure your infrastructure isn't vulnerable to #ToolShell (CVE-2025-53770) is half the job. The other half is validating that mitigations actually worked across your entire environment.

    Our Network Scanner provides immediate, targeted, and FAST detection for this 🔴 critical, unauthenticated RCE vulnerability:

    ✅ instantly scan your SharePoint servers with an effective, single-CVE scan
    ✅ quickly identify any remaining exposure to ToolShell, even after applying patches
    ✅ gain robust evidence (vulnerable endpoints, specific ports, validated findings) to confidently report on your security posture and prioritize remediation exactly where it's needed.

    Ready to act on it? Check out the resources below. 👇⬇️👇

    🔴 CVE details: pentest-tools.com/vulnerabilit

    👉 you can act on with our Network Scanner: pentest-tools.com/network-vuln "

  14. Chinese state-sponsored groups exploited SharePoint "Toolshell" zero-day (CVE-2025-53770) to compromise 100+ organizations across government and telecom sectors. The vulnerability allows complete system takeover without authentication. Microsoft patches available - update immediately.

    #SecurityLand #GeoSphere #CyberSecurity #SharePoint #Microsoft #ToolShell #APT #Government

    Read More: security.land/chinese-apt-grou

  15. Die aktuell laut #BSI bereits „massiv“ ausgenutzte #Toolshell-#Sicherheitslücke in #Microsoft #Sharepoint-Instanzen ist symptomatisch für die #Cybersecurity-Lage eines Konzerns, dessen Produktportfolio in den letzten Jahrzehnten organisch gewachsen ist und immer wieder durch Übernahmen und Zukäufe von Produkten und Diensten ergänzt wird – denn überall dort, wo Kontrolle und Verständnis über die eigene Software und IT fehlen, gibt es eben auch keine "Security by #Design":

    faz.net/aktuell/wirtschaft/unt

  16. Die aktuell laut #BSI bereits „massiv“ ausgenutzte #Toolshell-#Sicherheitslücke in #Microsoft #Sharepoint-Instanzen ist symptomatisch für die #Cybersecurity-Lage eines Konzerns, dessen Produktportfolio in den letzten Jahrzehnten organisch gewachsen ist und immer wieder durch Übernahmen und Zukäufe von Produkten und Diensten ergänzt wird – denn überall dort, wo Kontrolle und Verständnis über die eigene Software und IT fehlen, gibt es eben auch keine "Security by #Design":

    faz.net/aktuell/wirtschaft/unt

  17. ToolShell is actively being exploited and if you're running SharePoint on-prem, this is a real threat!

    Join our #CheckMates session tomorrow, Thursday, July 24 at 4 PM CET | 10 AM EST to learn how the exploit works, who's being targeted, and what you can do right now to protect your environment.

    We'll hear the latest insights from Check Point Research along with actionable steps.

    checkpoint.zoom.us/webinar/reg

    #ZeroDay #ToolShell #SharePoint #CyberSecurity #CheckPoint #CVE202553770 #ThreatIntel