<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sharepoint on CuraSec</title><link>https://curasec.metacog.co.kr/tags/sharepoint/</link><description>Recent content in Sharepoint on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/sharepoint/index.xml" rel="self" type="application/rss+xml"/><item><title>ThreatsDay Digest: IoT Botnet, Water Systems, SharePoint RCE</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-threatsday-296k-iot-botnet-100-water-systems-targeted-sharep/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-threatsday-296k-iot-botnet-100-water-systems-targeted-sharep/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> SharePoint RCE chain and AI-assisted botnet techniques are worth tracking, but the summary provides no CVE, EPSS, KEV, or patch target — read the full digest to identify whether any specific component you run is affected.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> C2 traffic hiding in public infrastructure and delayed-payload malware are tactically interesting detection themes, but no IOCs or ATT&amp;amp;CK mappings are surfaced here — use this as a prompt to review whether relevant log sources (DNS, proxy) would catch these patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The mention of over 100 water systems targeted is notable for critical-infrastructure sector awareness, but this is a vague digest with no specifics suitable for a leadership brief or risk-register update.&lt;/li>
&lt;/ul></description></item><item><title>Attackers exploit critical SharePoint vulnerability using public PoC</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC is live and attackers are already exploiting this critical SharePoint flaw — patch SharePoint on-prem deployments immediately and audit SharePoint ULS and IIS logs for anomalous authentication or anonymous access patterns from the PoC release date forward.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active in-the-wild exploitation means an immediate hunt is warranted — query SIEM for unusual SharePoint authentication events, abnormal REST/SOAP API calls, or unexpected file-access patterns since Rapid7&amp;rsquo;s PoC publication date, and tune alerts on SharePoint edge access.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A critical SharePoint vulnerability with a public PoC and confirmed exploitation warrants confirming on-prem SharePoint exposure with your engineering team and ensuring an emergency patch window is scheduled this week if not already done.&lt;/li>
&lt;/ul></description></item><item><title>SharePoint Auth Bypass CVE-2026-55040 Actively Exploited After PoC</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-attackers-exploit-sharepoint-authentication-bypass-after-pub/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-attackers-exploit-sharepoint-authentication-bypass-after-pub/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SharePoint CVSS 9.1 authentication bypass is now under active exploitation following public PoC release; apply Microsoft&amp;rsquo;s July 2026 Patch Tuesday update to all on-premises and hybrid SharePoint instances immediately and verify patch status in your estate.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of a SharePoint auth bypass means adversaries may already be inside unpatched tenants; hunt for anomalous SharePoint authentication events and unexpected file access patterns in audit logs dating back to the PoC release.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> SharePoint is ubiquitous in enterprise environments and this critical auth bypass is under active attack; confirm patch completion with engineering this week and assess whether any exposure window existed that could trigger customer notification obligations.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-55040 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>CVE-2026-55040: Unauthenticated RCE in SharePoint Server, PoC Public</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-researchers-disclose-ai-assisted-sharepoint-exploit-chain-re/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-researchers-disclose-ai-assisted-sharepoint-exploit-chain-re/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC on GitHub for a CVSS 9.1 unauthenticated RCE across SharePoint Server Subscription Edition, 2019, and 2016 means exploitation risk is immediate even without KEV listing; apply Microsoft&amp;rsquo;s patch for CVE-2026-55040 across all affected on-prem SharePoint instances this week.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No confirmed in-the-wild exploitation yet (EPSS 0.02, no KEV), but a public PoC for unauthenticated RCE warrants building SharePoint-specific detections now — hunt for anomalous unauthenticated requests to SharePoint REST/SOAP endpoints and tune alerts on privilege escalation patterns in SharePoint audit logs before active campaigns emerge.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A CVSS 9.1 unauthenticated RCE with public PoC against widely deployed SharePoint Server warrants confirming on-prem SharePoint scope with your team and ensuring patch prioritization this sprint — escalate to Act if exploitation is observed in the wild.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-55040 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Swiss government SharePoint breach compromised 200 accounts</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-swiss-government-sharepoint-breach-compromised-200-accounts/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-swiss-government-sharepoint-breach-compromised-200-accounts/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> SharePoint server vulnerabilities are plausible exposure for organizations running on-prem or hybrid SharePoint; audit your SharePoint patch level and review exposed endpoints, though no specific CVE or PoC is cited in available signals.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or TTPs are published yet, but a confirmed SharePoint breach compromising 200 accounts warrants building or tuning detections for SharePoint authentication anomalies and mass account access patterns in anticipation of further disclosure.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A nation-state-level SharePoint compromise affecting a federal government is a useful benchmark for board discussions on identity hygiene and on-prem collaboration platform risk, but no vendor exposure or regulatory deadline is triggered here.&lt;/li>
&lt;/ul></description></item><item><title>Critical SharePoint RCE CVE-2026-50522 Actively Exploited After PoC</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-critical-sharepoint-rce-cve-2026-50522-under-active-exploita/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-critical-sharepoint-rce-cve-2026-50522-under-active-exploita/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVSS 9.8 deserialization RCE with public PoC and confirmed active exploitation — patch SharePoint Server to the July 2026 Patch Tuesday build immediately; do not wait for CISA KEV confirmation given exploitation is already underway.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation predating your patch window means assume-breach posture is warranted — hunt for anomalous deserialization or code execution activity on SharePoint servers back to at least the PoC publication date, and review watchTowr&amp;rsquo;s reporting for any available IOCs or behavioral signatures.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A CVSS 9.8 unauthenticated RCE in widely-deployed enterprise SharePoint under active exploitation requires a same-week exposure check — confirm whether the org runs on-premises SharePoint Server and verify the engineering team has prioritized the July Patch Tuesday update.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources&lt;/li>
&lt;/ul></description></item><item><title>Critical SharePoint RCE exploited to steal machine keys for persistence</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active exploitation confirmed with a public GitHub PoC; patch SharePoint immediately AND regenerate machine keys — patching alone does not evict attackers who already exfiltrated them, so key rotation is the critical second step.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Stolen machine keys enable persistent, post-patch impersonation attacks — hunt SharePoint IIS logs for exploitation artifacts since the vulnerability became public, and write detections for anomalous ViewState or token-forging activity tied to mismatched machine keys.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm SharePoint is in scope, then ensure your engineering team understands that patching alone is insufficient — key rotation and a post-exploitation sweep are required; flag this as a two-step remediation so it isn&amp;rsquo;t closed prematurely in the ticket queue.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources&lt;/li>
&lt;/ul></description></item><item><title>CISA KEV: SharePoint RCE Zero-Day CVE-2026-58644 Actively Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-cisa-adds-exploited-sharepoint-rce-zero-day-cve-2026-58644-t/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-cisa-adds-exploited-sharepoint-rce-zero-day-cve-2026-58644-t/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SharePoint Server CVE-2026-58644 (CVSS 9.8) is KEV-listed with active exploitation and a public GitHub PoC — patch immediately; federal deadline is July 19, 2026, so treat this as emergency priority regardless of your organization type.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With active exploitation confirmed and a public PoC live, treat any on-prem SharePoint Server as potentially compromised — sweep SharePoint ULS/IIS logs for deserialization anomalies and unusual POST requests to SharePoint endpoints since the vulnerability was disclosed.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A CVSS 9.8 SharePoint RCE is actively exploited and KEV-listed with a two-day federal remediation deadline — confirm this week whether your environment runs SharePoint Server on-prem and verify the engineering team has emergency patching underway before the July 19 deadline.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-58644 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>CISA: Three SharePoint Server flaws actively exploited in the wild</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-cisa-warns-admins-to-patch-actively-exploited-sharepoint-fla/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-cisa-warns-admins-to-patch-actively-exploited-sharepoint-fla/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA warning indicates KEV-level active exploitation against internet-exposed on-premises SharePoint Server. Apply Microsoft&amp;rsquo;s patches immediately and verify no externally reachable SharePoint instances remain unpatched.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of internet-facing SharePoint means assume-breach posture is warranted; hunt for post-exploitation activity (lateral movement, credential access) on SharePoint hosts since the earliest known exploitation date and review IIS/ULS logs for anomalous request patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether the organization runs on-premises SharePoint Server exposed to the internet, and get a patching status update from engineering this week — active exploitation with a CISA advisory is the kind of event that surfaces in board or customer security reviews.&lt;/li>
&lt;/ul></description></item></channel></rss>