Google TIG is tracking active exploitation of a #SharePoint Zero-Day vulnerability. #Microsoft released CVE-2025-53770 to track the vulnerability in on-premise SharePoint servers that is being exploited. Threat actors install #webshells and exfiltrate cryptographic MachineKey secrets.