Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by SafeBreach. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by SafeBreach or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Ep. 4: ToolShell in the Wild: SharePoint Zero-Day CVE-2025-53770 Explained

10:53
 
Share
 

Manage episode 495676207 series 3675440
Content provided by SafeBreach. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by SafeBreach or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In this urgent Cyber Resilience Brief, host Tova Dvorin is joined by SafeBreach experts Adrian Culley and Tomer Bar to break down CVE-2025-53770, a critical zero-day vulnerability actively exploited in Microsoft SharePoint Server. Known as part of the ToolShell attack chain, this deserialization flaw allows unauthenticated remote code execution and persistence β€” and it’s already being used in the wild.

We discuss:

  • What makes this vulnerability so dangerous (hint: there's no patch for SharePoint 2016 yet)

  • Why Microsoft is advising customers to assume breach

  • How SafeBreach Labs responded within 24 hours with new BAS coverage

  • Specific indicators of compromise (IoCs) and mitigation advice

  • Why this attack demands urgent attention from security teams and CISOs alike

Whether you're a SafeBreach customer or just trying to stay ahead of emerging threats, this episode delivers the critical insights you need β€” fast.

πŸ”— For more information on today's CVE, check out our post on the SafeBreach blog.

  continue reading

6 episodes

Artwork
iconShare
 
Manage episode 495676207 series 3675440
Content provided by SafeBreach. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by SafeBreach or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.

In this urgent Cyber Resilience Brief, host Tova Dvorin is joined by SafeBreach experts Adrian Culley and Tomer Bar to break down CVE-2025-53770, a critical zero-day vulnerability actively exploited in Microsoft SharePoint Server. Known as part of the ToolShell attack chain, this deserialization flaw allows unauthenticated remote code execution and persistence β€” and it’s already being used in the wild.

We discuss:

  • What makes this vulnerability so dangerous (hint: there's no patch for SharePoint 2016 yet)

  • Why Microsoft is advising customers to assume breach

  • How SafeBreach Labs responded within 24 hours with new BAS coverage

  • Specific indicators of compromise (IoCs) and mitigation advice

  • Why this attack demands urgent attention from security teams and CISOs alike

Whether you're a SafeBreach customer or just trying to stay ahead of emerging threats, this episode delivers the critical insights you need β€” fast.

πŸ”— For more information on today's CVE, check out our post on the SafeBreach blog.

  continue reading

6 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Copyright 2025 | Privacy Policy | Terms of Service | | Copyright
Listen to this show while you explore
Play