ポッドキャスト収録用のメモですよ。
podcast - #セキュリティのアレ - ゆるーいセキュリティのポッドキャストですよ。
事件、事故
フランスとウクライナの法執行機関および Europol の協力により、XSS フォーラムの管理者を逮捕
A long-running investigation led by the French Police and Paris Prosecutor, in close cooperation with their Ukrainian counterpart and Europol, has led to the arrest of the suspected administrator of xss.is, one of the world’s most influential Russian-speaking cybercrime platforms.
(7/23) Ukraine arrests suspected admin of XSS Russian hacking forum
(7/24) XSS Forum Seized: KELA Reveals User Reactions and Speculations | KELA Cyber
BlackSuit ランサムウェアのサイトが法執行機関によって差し押さえ
(7/24) BlackSuit ransomware extortion sites seized in Operation Checkmate
攻撃、脅威
CISA などが共同で Interlock ランサムウェアに関する注意喚起
(7/22) Joint Advisory Issued on Protecting Against Interlock Ransomware | CISA
Coveware が 2025年第 2 四半期のランサムウェアレポートを公開
(7/23) Targeted social engineering is en vogue as ransom payment sizes increase
脆弱性
Microsoft SharePoint Server に脆弱性。すでに悪用が確認されている
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security Update.
Microsoft has released security updates that fully protect customers using all supported versions of SharePoint affected by CVE-2025-53770 and CVE-2025-53771. Customers should apply these updates immediately to ensure they’re protected.
These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.
(7/19) SharePoint Under Siege: ToolShell Mass Exploitation (CVE-2025-53770)
On the evening of July 18, 2025, Eye Security identified active, large-scale exploitation of a new SharePoint remote code execution (RCE) vulnerability chain, dubbed ToolShell, demonstrated just days ago on X, this exploit is being used in the wild to compromise on-premise SharePoint servers across the world. The new chain we elaborate in this blog, was later named CVE-2025-53770 by Microsoft.
(7/20) Microsoft Releases Guidance on Exploitation of SharePoint Vulnerability (CVE-2025-53770) | CISA
(7/20) Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
(7/22) Disrupting active exploitation of on-premises SharePoint vulnerabilities | Microsoft Security Blog
As early as July 7, 2025, Microsoft analysis suggests threat actors were attempting to exploit CVE-2025-49706 and CVE-2025-49704 to gain initial access to target organizations. These actors include Chinese state actors Linen Typhoon and Violet Typhoon and another China-based actor Storm-2603. The TTPs employed in these exploit attacks align with previously observed activities of these threat actors.
(7/24) SharePoint ToolShell – One Request PreAuth RCE chain CVE-2025-53770
(7/24) ToolShell - A Critical SharePoint Vulnerability Chain under Active Exploitation
Microsoft SharePoint Serverの脆弱性CVE-2025-53770 通称 ToolShellが大規模に悪用されているとのことでグローバルの脆弱サーバ分布を調査。Sharepointサーバはグローバル7877台あり、内 2403台が影響をうけるエディション/2016,2019,Subscriptionを利用、更に2052台が本日調査時点で脆弱性未対処 pic.twitter.com/v2d9Llq1U6
— nekono_nanomotoni (@nekono_naha) July 22, 2025
Thanks to a scan conducted by @leak_ix, we have shared SharePoint IPs confirmed vulnerable to CVE-2025-53770, CVE-2025-53771.
— The Shadowserver Foundation (@Shadowserver) July 24, 2025
424 SharePoint IPs found on 2025-07-23. One-off data in our Vulnerable HTTP report - https://t.co/qxv0Gv5ELc
Tree map: https://t.co/e8WGDJEwgh pic.twitter.com/xwDzHIPE98
CISA が Known Exploited Vulnerabilities (KEV) カタログに 1+2+4 個の脆弱性を追加
(7/20) CISA Adds One Known Exploited Vulnerability, CVE-2025-53770 “ToolShell,” to Catalog | CISA
- CVE-2025-53770: Microsoft SharePoint Server Remote Code Execution Vulnerability
(7/22) CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA
- CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability
- CVE-2025-49706 Microsoft SharePoint Improper Authentication Vulnerability
(7/22) CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA
- CVE-2025-54309 CrushFTP Unprotected Alternate Channel Vulnerability
- CVE-2025-6558 Google Chromium ANGLE and GPU Improper Input Validation Vulnerability
- CVE-2025-2776 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
- CVE-2025-2775 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability