Microsoft has issued urgent warnings about active exploitation of critical SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 by multiple threat actors, including the China-based group Storm-2603, which has been deploying Warlock ransomware in compromised environments. Post-exploitation activities involve abuse of the w3wp.exe process that supports SharePoint, with attackers using cmd.exe and services.exe to disable Microsoft Defender protections through direct registry modifications. The attack chain begins with the exploitation of CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution flaw affecting internet-facing SharePoint servers. Storm-2603 establishes persistence through multiple mechanisms, including scheduled tasks and manipulation of Internet Information Services (IIS) components to load suspicious .NET assemblies.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 25 Jul 2025 07:50:19 +0000