Cloudflare mitigated a record-breaking Distributed Denial-of-Service (DDoS) attack in mid-May 2025, which peaked at 7.3 terabits per second (Tbps) and delivered 37.4 terabytes (TB) of junk traffic in just 45 seconds. This attack targeted a hosting provider and primarily exploited UDP protocols for rapid data delivery. The event marks the largest DDoS attack ever recorded, highlighting a sharp rise in the scale and sophistication of cyber assaults. Alongside this, Microsoft released its July 2025 Patch Tuesday security update, addressing 130 vulnerabilities across its products and Windows systems. Notably, none of these vulnerabilities have been actively exploited in the wild. However, a critical unpatched zero-day vulnerability in Microsoft SharePoint (CVE-2025-53770) is currently being actively exploited by malicious actors, compromising at least 75 organizations globally, including major companies and governments. This ongoing SharePoint attack, known as "ToolShell," allows unauthenticated remote code execution and full access to SharePoint content, with no patch available yet. Security agencies and experts urge immediate mitigation actions to protect affected systems.
SharePoint 0‑Day Strikes BleepingComputer: CVE‑2025‑53770 exploited, 85 servers hit, no patch yet, as of July 20, 2025. https://t.co/XILaPCyenP Is AI‑driven defense ready for old‑school exploits? #AI #Robotics #News For more AI News, follow @dylan_curious on YouTube.
SharePoint Server attack alert. https://t.co/FmqA0SRZg1
This exploitation activity, publicly reported as “ToolShell,” provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content. Take action now 👉 https://t.co/sMS6lbaYCs https://t.co/DMiDt05Z5b