Widespread Attacks Target Microsoft SharePoint Zero-day Vulnerability

October 8, 2025

INCIDENT

Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. They used this exploit chain (dubbed "ToolShell") to breach dozens of organizations worldwide after hacking into their on-premise SharePoint servers.

Dutch cybersecurity firm Eye Security first spotted zero-day attacks exploiting the CVE-2025-49706 and CVE-2025-49704 vulnerabilities (first demoed during the Berlin Pwn2Own hacking contest by Viettel Cyber Security researchers). The company told BleepingComputer that at least 54 organizations had already been compromised, including several multinational companies and national government entities.

Incident Date

July 18, 2025

Estimated Cost


No cost values disclosed.

Victims

Type of Malware

No Malware identified

Threat Source

No threat source identified