SharePoint, active exploitation
Digest more
The name was coined by Dinh Ho Anh, a researcher from Khoa of Viettel Cyber Security, who developed the exploit. The researcher said he picked the name because it exploited ToolPane.aspx, a component for assembling the side panel view in the SharePoint user interface.
More information has emerged on the ToolShell SharePoint zero-day attacks, including impact, victims, and threat actors.
Active SharePoint exploits since July 7 target governments and tech firms globally, risking key theft and persistent access.
State CISOs in North Carolina and Arizona said their teams began work immediately to ensure on-prem SharePoint systems were secure, following the recent disclosure of an active zero-day exploit.
CISA gave agencies until the end of the day on Monday to mitigate a severe zero-day vulnerability in Microsoft's widely used SharePoint software.
Governments, schools, healthcare providers and large enterprise firms are at risk, one cyber threat intelligence chief said.