fromZDNET
1 week agoMicrosoft fixes two SharePoint zero-days under attack, but one is still unresolved - how to patch
CVE-2025-53770 gives a threat actor the ability to remotely execute code, bypassing identity protections (like single sign-on and multi-factor authentication), giving access to content on the SharePoint server including configurations and system files, opening up lateral access across the Windows domain.
Information security