Episode

ToolShell Deep Dive: The SharePoint Exploit Crisis Uncovered

Podcast
Infosecurity Magazine Podcast
Published
Jul 28, 2025
Duration seconds
2507
Processing state
not_requested
Canonical source
https://soundcloud.com/user-460162468/infosecurity-podcast-toolshell-july-2025
Audio
https://feeds.soundcloud.com/stream/2137306338-user-460162468-infosecurity-podcast-toolshell-july-2025.mp3
JSON
/v1/public/podcasts/infosecurity-magazine-podcast-1181101/episodes/toolshell-deep-dive-the-sharepoint-exploit-crisis-uncovered
Markdown
/podcast/infosecurity-magazine-podcast-1181101/toolshell-deep-dive-the-sharepoint-exploit-crisis-uncovered.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/infosecurity-magazine-podcast-1181101/episodes/toolshell-deep-dive-the-sharepoint-exploit-crisis-uncovered/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/infosecurity-magazine-podcast-1181101/toolshell-deep-dive-the-sharepoint-exploit-crisis-uncovered.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this special episode of the Infosecurity Magazine podcast, we dive deep into the rapidly evolving story surrounding Microsoft SharePoint On-Premises. Recent disclosures have revealed a series of vulnerabilities now being exploited in targeted campaigns, with Chinese threat actors at the centre but other threat actors joining in the attacks. This episode breaks down the complexities of the incident, the ongoing exploitations and the broader implications for security practitioners. Stay updated as this story unfolds and equip yourself with valuable insights to better understand and defend against emerging cyber threats. Our discussion includes: Timeline of events surrounding the ToolShell Microsoft SharePoint on-prem vulnerability (02.20) Interview with Charles Carmakal, CTO at Mandiant, now part of Google Cloud (06.38). Charles details these critical vulnerabilities and steps towards patching and what some orgnaizations may be missing, leaving them vulnerable to compromise. Interview Lorri Janssen-Anessi, Director of External Cyber Assessments at BlueVoyant. With extensive experience from her time at the NSA and the Department of Homeland Security, Lorri provides an in-depth perspective on the impact these attacks are having and what they mean for organizations today. (17.18) Sing up to receive Infosecurity Magazine's weekly newsletter here.