Category: Cyber-Physical Security

Coverage of the convergence between IT/cybersecurity and physical security systems, including networked device risk, secure system integration and unified threat response.

  • CISA Confirms Active Exploitation of SharePoint ToolShell Vulnerability

    CISA Confirms Active Exploitation of SharePoint ToolShell Vulnerability

    July 20, 2025 — CISA added SharePoint Server CVE-2025-53770 to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

    What happened

    CISA added CVE-2025-53770, known as ToolShell, to the Known Exploited Vulnerabilities catalog and published guidance for affected on-premises Microsoft SharePoint environments. Later analysis described malicious files, web shells and attempts to extract cryptographic material. The issue concerned on-premises SharePoint Server, not Microsoft 365 SharePoint Online.

    Why it matters

    The incident demonstrates why collaboration platforms are high-value targets: they combine trusted identities, sensitive documents and connectivity to internal systems. A successful compromise may survive a simple software update if attackers have already installed persistence or stolen keys.

    Security and infrastructure impact

    Organizations should apply Microsoft and CISA guidance, hunt for published indicators, rotate exposed secrets where required and isolate affected systems during investigation. Recovery should include evidence review, not only patch installation.

    Sources

    ← Back to Technology News

  • CitrixBleed 2 Puts NetScaler Session Security Back Under Pressure

    CitrixBleed 2 Puts NetScaler Session Security Back Under Pressure

    June–July 2025 — The NetScaler vulnerability known as CitrixBleed 2 renewed attention on exposed edge appliances, session-token theft and post-patch incident response.

    What happened

    Security researchers used the name CitrixBleed 2 for a NetScaler ADC and Gateway vulnerability capable of exposing sensitive memory and session material under affected conditions. Citrix issued security updates and operational guidance. Because victim counts changed across investigations, this article does not repeat the hub’s earlier unverified “more than 100 organizations” figure.

    Why it matters

    Session-token exposure can let an attacker bypass the protection users expect from passwords and multifactor authentication. Patching closes the known flaw, but it may not invalidate tokens or remove persistence created before remediation.

    Security and infrastructure impact

    Defenders should follow vendor guidance, restrict management exposure, terminate relevant sessions, rotate credentials where indicated and review logs for abnormal access. Internet-facing security appliances should be included in rapid asset inventory and emergency patch processes.

    Sources

    ← Back to Technology News