DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise;
SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise;

SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise;

Update: 2025-07-24
Share

Description



Reversing SharePoint Toolshell Exploits CVE-2025-53770 and CVE-2025-53771

A quick walk-through showing how to decode the payload of recent SharePoint exploits

https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138

Compromised JavaScript NPM is Package

The popular npm package is was compromised by malware. Luckily, the malicious code was found quickly, and it was reversed after about five hours.

https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack

Microsoft Quick Machine Recovery

Microsoft added a new quick machine recovery feature to Windows 11. If the system is stuck in a reboot loop, it will boot to a rescue partition and attempt to find fixes from Microsoft.

https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise;

SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise;

Dr. Johannes B. Ullrich