Critical SharePoint Zero-Day Exploited
The active exploitation campaign targeting CVE-2025-53770 in Microsoft SharePoint Server demonstrates a sophisticated attack vector that leverages a fundamental weakness in how the software processes data. Attackers exploiting this bug are not merely injecting arbitrary code; they are specifically abusing how SharePoint deserializes untrusted objects. Deserialization is the process of converting data from a stream of bytes back into an object in memory. When […]