SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused

5 snips
Jul 22, 2025
Microsoft patched a critical SharePoint vulnerability, introducing an authentication bypass CVE. A review of patching speeds shows they could be improved. Meanwhile, HPE addressed vulnerabilities in its access points that allowed for risky exploits. Concerns were raised about a bug in AppLocker policies that could lead to bypassing security rules. Additionally, the Ghost Crypt malware is using Zoho WorkDrive to trick users into downloading malicious files.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Urgent SharePoint Patch Advice

  • Patch your SharePoint Server immediately if using the subscription edition or Server 2019 and assume compromise if on 2016 with no patch yet.
  • Avoid overly specific payload detection since attackers can easily generate new payloads using .NET YSO Serializer.
ADVICE

Patch HP Aruba Access Points Now

  • Apply HP patches for Aruba Instant On access points to fix authentication bypass and code execution bugs.
  • Remember that combining the auth bypass with code exec vulnerability enables full admin remote code execution.
INSIGHT

Visibility Risk of Critical Vulns

  • Critical vulnerabilities like SharePoint can overshadow other serious but less visible issues.
  • This cycle risks missing other important patches such as those for HP Instant On access points.
Get the Snipd Podcast app to discover more snips from this episode
Get the app