CISA adds four actively exploited flaws covering macOS, SharePoint, vCenter, and Microsoft IKE to its urgent patch catalog.
New Windows implant TWINLOOT abuses SharePoint and Teams to steal credentials and move laterally.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
Swiss federal IT office BIT resets roughly 200 accounts after a Microsoft SharePoint credential theft.
Attackers are exploiting a critical SharePoint RCE vulnerability to steal machine keys, and patching alone won't lock them out.
CISA warns of active exploitation of CVE-2026-58644 and three other SharePoint flaws, urging federal agencies to patch within a week.
Microsoft's July 2026 Patch Tuesday fixes 622 CVEs including exploited SharePoint and AD FS zero-days
The Helix group uses vishing and device code phishing to break into SharePoint, then exfiltrates data for extortion or sale.