惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - Franky
Apple Machine Learning Research
Apple Machine Learning Research
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
量子位
雷峰网
雷峰网
宝玉的分享
宝玉的分享
V
Visual Studio Blog
博客园_首页
小众软件
小众软件
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
S
SegmentFault 最新的问题
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学

Security Research | Blog

SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabz Microsoft Exchange Vulnerability: What Admins Should Do C2Looper Backdoor Uses GitHub for C2 | ThreatLabz Midnight Blizzard launches CaptiveCrunch | ThreatLabz ChainDrop NPM Worm Analysis | ThreatLabz Abyssos Modular RAT Analysis | ThreatLabz Frontier AI and Enterprise Readiness | Zscaler Ransomware Victims Research | ThreatLabz Targeted Attack on Middle East Govts (Part 2) | ThreatLabz Technical Analysis of GoGRPC | ThreatLabz Targeted Attack on Middle East Govts (Part 1) | ThreatLabz ClaudeFix: Shared Claude Chats Meet ClickFix | Zscaler Why Do F1 Teams Need Cybersecurity, and What Is AI’s Role? Indirect Prompt Injection Targets AI Agents | ThreatLabz Splunk Enterprise RCE (CVE-2026-20253) | ThreatLabz Edgecution: Malicious Edge Extension Backdoor | ThreatLabz SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler Shai-Hulud: Miasma, Hades, & AI Scanner Evasion | ThreatLabz Zscaler ThreatLabz 2026 Phishing and Initial Access Report Technical Analysis of MLTBackdoor | ThreatLabz When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing | Zscaler OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz Tropic Trooper: AdaptixC2 + Custom Beacon | ThreatLabz Do not delete blog (testing) | Zscaler Payouts King Takes Aim at the Ransomware Throne | ThreatLabz The Alibaba Incident and Why Zero Trust Matters More Than Ever In-Memory Loader Drops ScreenConnect | ThreatLabz Supply Chain Attacks Surge in March 2026 | ThreatLabz
CVE-2025-53770 | ThreatLabz
Avinash Kumar, Rohit Hegde, Varun Sandila, Sakshi Aggarwal · 2025-07-22 · via Security Research | Blog

How Zscaler Protects Against CVE-2025-53770

Zscaler Deception empowers organizations to proactively intercept targeted attacks, including zero-day vulnerabilities like CVE-2025-53770, even before they are publicly disclosed. By deploying perimeter-facing decoys, Zscaler emulates commonly targeted applications such as VPNs, firewalls, and SharePoint. These decoys are designed to only respond when they are specifically targeted via hostnames, avoiding detection during random internet scans. This approach provides early threat signals while enabling security teams to respond swiftly and block attackers before they can infiltrate or compromise an environment.

Zscaler Deception customers benefited from early detection of CVE-2025-53770 being actively exploited, with the first signs appearing on the morning of July 17th, four days ahead of the advisory issued by CISA. Through SharePoint decoys, Zscaler Deception identified malicious activity and uncovered the following IPs attempting to exploit the vulnerability:

  • 213.130.140.84
  • 154.47.29.4
  • 104.238.159.149
  • 107.191.58.76
  • 139.144.199.41
  • 96.9.125.147
  • 185.189.25.230

If you are a Zscaler customer, we strongly recommend reaching out to your account manager to deploy SharePoint decoys. These decoys provide robust early-detection capabilities while serving as valuable sources of threat intelligence, critical for investigating and triaging relevant incidents.

Stopping lateral movement with Deception + Zscaler Private Access (ZPA):

Zscaler’s SharePoint decoys can also be deployed within ZPA environments and server VLANs to detect and stop lateral movement. This integrated solution enables Zscaler Deception to identify attackers attempting to pivot from compromised endpoints to internal SharePoint applications. As soon as such activity is detected, ZPA takes immediate action by isolating the compromised user or malicious insider, effectively preventing access to high-value assets or crown jewel applications.

By leveraging the combined power of Zscaler Deception and ZPA, organizations can significantly harden their environments against exploitation attempts and mitigate risks associated with lateral movement.