Serious vulnerabilities now get exploited within 24–48 hours of disclosure. Some forecasts say minutes by 2028.
During the SharePoint ToolShell zero-day, thousands of servers were still exposed to the internet — many unnecessarily.
🔗 Why attack surface exposure gets missed → thehackernews.com/2026/03/th…
"In 2025, the activity varied by region and objective. In the Americas, attackers invested in high-value targets, including early ToolShell exploitation assessed as Chinese-nexus activity against North American government organizations."
2025 has seen many great web security findings.
Honored that @_l0gg's SharePoint ToolShell pre-auth RCE (CVE-2025-53770) is nominated for @PortSwigger Top 10 Web Hacking Techniques 2025.
If you're in the community, your vote would mean a lot: portswigger.net/polls/top-10…
Thanks!
I know it's a little bit late, but here is my go on the ToolShell vulns:
github.com/LuemmelSec/ToolSh…
However, this tool is also capable of giving you an interactive shell without file writes if you have the Machine keys, so not just useful for exploiting ToolShell alone.
Actor Exploiting ToolShell Vulnerability (SharePoint CVE-2025-53770)
AS 213799 ( Conhost Bilgi Teknolojileri Veri Merkezi Hizmetleri Ve Danismanlik Limited Sirketi ) 🇹🇷
0/95 Detections on VT 🟢
Link 👇console.defusedcyber.com/s/9…
Second part of a two-part @HuntressLabs blog series is here, which looks at several incidents where the threat actor used the Velociraptor DFIR tool - featuring ToolShell, Warlock ransomware, and a series of attacker fumbles. @darkrym11huntress.com/blog/velocirapt…
#DFIR#Blue_Team_Techniques#Purple_Team_Exercises
1⃣ Hunting for SharePoint In-Memory ToolShell Payloads (CVE-2025-53770, CVE-2025-53771)
isc.sans.edu/diary/Guest Dia…
// A walk-through showing how to analyze ToolShell payloads, starting with acquiring packets all the way to decoding embedded PowerShell commands
2⃣ Bind Link - EDR Tampering
ipurple.team/2025/12/01/bind…
// Threat actors exploit Windows Bind Link API to redirect EDR folders, enabling DLL hijacking and evasion, which can be detected through monitoring bindfltapi.dll loads, API calls, and leveraging EDR solutions' monitoring capabilities
Since we're covering this tomorrow at @NDC_Conferences Manchester, I’ve released the bypass for the ToolShell SharePoint deserialization exploit in ysonet.net (same bug @_l0gg originally showed).
“Complex” bypass? 🥵
Just a single whitespace. 👻
Something we even knew from the past: zerodayinitiative.com/blog/2…😶🌫️
SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packets; Android Update; Long Game Malicious Browser Ext.
isc.sans.edu/podcastdetail/9…