Shared Security Podcast
Shared Security Podcast
Tom Eston, Scott Wright, Kevin Tackett
Leaked, Patched, and Still Hacked: The SharePoint Zero-Day Crisis
15 minutes Posted Aug 4, 2025 at 4:00 am.
Leaked, Patched, and Still Hacked: The SharePoint Zero-Day Crisis
Introduction: A Tale of Patchwork and Paranoia
Microsoft's SharePoint Patch Vulnerability
US Agencies Compromised by Cyber Espionage
Discussion on SharePoint Vulnerability
Understanding the On-Prem SharePoint Vulnerability
Microsoft's Patch Evaluation Issues
The MAPP Leak Speculation
SharePoint's Long History of Vulnerabilities
Looking Ahead: Future Patches and Conferences
Conclusion: Stay Safe, Stay Secure
0:00
15:48
Download MP3
Show notes
This week we explore the recent Microsoft SharePoint vulnerability that has led to widespread exploitation by ransomware gangs and Chinese State-sponsored hackers. We also cover the confirmed compromise of multiple US agencies, including the Department of Homeland Security, in a large-scale cyber espionage campaign. Kevin Johnson joins to discuss the implications of these events, the underlying issues with patching systems, and the complexities of protecting applications like SharePoint. Stay informed on the latest cybersecurity developments and get insights on what might have gone wrong. Plus, get a peek at what’s happening at Black Hat and DEF CON in Vegas.