this post was submitted on 23 Jul 2025
149 points (97.5% liked)

Technology

73066 readers
2445 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Security researchers at Google and Microsoft say they have evidence that hackers backed by China are exploiting a zero-day bug in Microsoft SharePoint, as companies around the world scramble to patch the flaw.

The bug, known officially as CVE-2025-53770 and discovered last weekend, allows hackers to steal sensitive private keys from self-hosted versions of SharePoint, a software server widely used by companies and organizations to store and share internal documents. Once exploited, an attacker can use the bug to remotely plant malware and gain access to the files and data stored within, as well as gain access to other systems on the same network.

you are viewing a single comment's thread
view the rest of the comments
[–] Oisteink 31 points 9 hours ago (3 children)

That’s not a zero-day… Really dislike media that waters down or misuse terminology

[–] Senseless@feddit.org 10 points 7 hours ago

So that would make it a zero-oneandahalf-week.

[–] theunknownmuncher@lemmy.world 5 points 8 hours ago

It's not just media. The number of software engineers I've heard talk about "fixing" a "zero day" in a code dependency by updating to a patched version...

[–] theneverfox@pawb.social 4 points 9 hours ago (1 children)

Well, it's a zero day for 24 hours, right?

[–] Oisteink 12 points 9 hours ago (1 children)

Yepp - it was, but that day was 11. June

[–] Passerby6497@lemmy.world 17 points 9 hours ago* (last edited 3 hours ago) (2 children)

I don't think that's true either, based on the reporting it's based on a bug disclosed at a hacking conference in May. No clue how this is a zero day if it's based on a 2 month old bug reported to the vendor.

Seems more like bog standard Microsoft fucking around and waiting too long to patch before it got used.

[–] 100@fedia.io 6 points 8 hours ago

wonder if they got a case to sue for damages if microsoft has been slow at dealing with the issue

[–] purplemonkeymad@programming.dev 1 points 8 hours ago

Iirc there was a previous attempt to patch this, it would appear a slight variation was not fixed in the patch. Might be why people are saying zero day.