ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

Released Monday, 28th July 2025
Good episode? Give it some love!
ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

Monday, 28th July 2025
Good episode? Give it some love!
Rate Episode
List

In this special episode of the Infosecurity Magazine podcast, we dive deep into the rapidly evolving story surrounding Microsoft SharePoint On-Premises.

Recent disclosures have revealed a series of vulnerabilities now being exploited in targeted campaigns, with Chinese threat actors at the centre but other threat actors joining in the attacks.

This episode breaks down the complexities of the incident, the ongoing exploitations and the broader implications for security practitioners. Stay updated as this story unfolds and equip yourself with valuable insights to better understand and defend against emerging cyber threats.

Our discussion includes:

Timeline of events surrounding the ToolShell Microsoft SharePoint on-prem vulnerability (02.20)Interview with Charles Carmakal, CTO at Mandiant, now part of Google Cloud (06.38). Charles details these critical vulnerabilities and steps towards patching and what some orgnaizations may be missing, leaving them vulnerable to compromise.Interview Lorri Janssen-Anessi, Director of External Cyber Assessments at BlueVoyant. With extensive experience from her time at the NSA and the Department of Homeland Security, Lorri provides an in-depth perspective on the impact these attacks are having and what they mean for organizations today. (17.18)Sing up to receive Infosecurity Magazine's weekly newsletter here.

Show More