

SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused
5 snips Jul 22, 2025
Microsoft patched a critical SharePoint vulnerability, introducing an authentication bypass CVE. A review of patching speeds shows they could be improved. Meanwhile, HPE addressed vulnerabilities in its access points that allowed for risky exploits. Concerns were raised about a bug in AppLocker policies that could lead to bypassing security rules. Additionally, the Ghost Crypt malware is using Zoho WorkDrive to trick users into downloading malicious files.
AI Snips
Chapters
Transcript
Episode notes
Urgent SharePoint Patch Advice
- Patch your SharePoint Server immediately if using the subscription edition or Server 2019 and assume compromise if on 2016 with no patch yet.
- Avoid overly specific payload detection since attackers can easily generate new payloads using .NET YSO Serializer.
Patch HP Aruba Access Points Now
- Apply HP patches for Aruba Instant On access points to fix authentication bypass and code execution bugs.
- Remember that combining the auth bypass with code exec vulnerability enables full admin remote code execution.
Visibility Risk of Critical Vulns
- Critical vulnerabilities like SharePoint can overshadow other serious but less visible issues.
- This cycle risks missing other important patches such as those for HP Instant On access points.