The cruelest kind of security failure is the one you thought you'd already fixed. On July 8, 2025, Microsoft's Patch Tuesday shipped fixes for a pair of SharePoint flaws demonstrated back in May at the Pwn2Own contest in Berlin. Ten days later, on the evening of July 18, the Dutch firm Eye Security caught attackers exploiting SharePoint anyway — through a chain, quickly named ToolShell, that simply stepped around the July 8 patch. The centrepiece, CVE-2025-53770, was a remote-code-execution flaw in on-premises SharePoint; paired with CVE-2025-53771, it let an unauthenticated attacker take a server whole.
What made ToolShell more than a bad weekend was what it stole. The attackers pulled the ASP.NET machine keys off compromised servers — the cryptographic secrets a SharePoint server uses to sign and trust its own data. With those keys, an intruder can forge trusted payloads at will and walk back in after the server is patched. Patching closed the door; it didn't change the locks. Only on-premises SharePoint was affected — SharePoint Online in Microsoft 365 was not — but on-prem is exactly where governments and large enterprises keep their most sensitive internal sites. Eye Security counted 54 compromised organisations in the first weekend; within days the tally climbed past 400 as Microsoft rushed emergency patches out between July 20 and 22, and CISA added the flaw to its Known Exploited Vulnerabilities list on July 20.
On July 22, Microsoft attributed the exploitation to Chinese state-affiliated groups — Linen Typhoon, Violet Typhoon, and the China-based Storm-2603, which by late July was seen deploying Warlock ransomware through the same holes. Press reporting placed the US Department of Education, Florida's Department of Revenue, and the Rhode Island General Assembly among the victims. Then, on July 23, Bloomberg reported that the National Nuclear Security Administration — the agency that maintains America's nuclear arsenal — was among those breached. Energy Department officials said the impact was minimal and no sensitive or classified information was known to be compromised. That it needed saying at all was the story.
Qantas, Allianz, and a $380 million lawsuit
Away from the SharePoint fire, July confirmed a quieter epidemic: attackers talking their way into help desks. Qantas disclosed on July 2 that an intruder had reached a third-party platform used by its Manila call centre, and on July 9 confirmed roughly 5.7 million customers' data was taken — names, emails, birth dates, frequent-flyer numbers, but no passwords or financial data. Allianz Life confirmed a July 16 social-engineering attack on its Salesforce CRM exposed data on most of its customers, later counted at 1,497,036 people. Both were tied by researchers to the ShinyHunters Salesforce data-theft campaign. And on July 22, Clorox sued IT provider Cognizant for about $380 million, alleging its help desk had reset employee passwords and MFA for Scattered Spider callers without verifying who they were — putting a dollar figure on the year's favourite attack technique: asking nicely.
Ingram Micro and the SafePay outage
On July 3, Ingram Micro — one of the world's largest IT distributors, roughly $48 billion in annual revenue — began a global outage of its website and ordering systems. It confirmed ransomware on July 5, with the SafePay gang claiming responsibility and initial access reportedly through compromised GlobalProtect VPN credentials. Operations were restored by around July 9, after six days of disruption spanning the US holiday weekend. It was September's Jaguar Land Rover lesson in miniature, two months early: when the company that moves everyone's products stops moving, a whole channel stops with it.
CoinDCX loses $44 million — in the same July as last time
On July 19, 2025, Indian crypto exchange CoinDCX suffered a roughly $44 million theft from an internal liquidity-provisioning account used with a partner exchange — a breach CEO Sumit Gupta described as a sophisticated server compromise. Customer funds in cold wallets were untouched, and CoinDCX said it would absorb the entire loss from its own treasury. The awkward detail was the disclosure timing: the theft only became public after blockchain investigator ZachXBT flagged it roughly 17 hours later, after which CoinDCX posted a 25% recovery bounty. And the eerie one was the date — almost exactly one year after the July 18, 2024 WazirX hack that drained around $230 million, giving India two major exchange breaches in consecutive Julys, and its regulators one more argument that crypto custody is a systemic question, not a niche one.
⏳ Time capsule — July 2025
- On July 9, Nvidia became the first company in history to touch a $4 trillion market capitalisation.
- Bitcoin crossed $120,000 around July 14; on July 18 the US signed the GENIUS Act, its first federal stablecoin law, capping Washington's "Crypto Week."
- Astronomers announced comet 3I/ATLAS on July 1 — only the third interstellar object ever seen crossing our solar system.
- A Coldplay concert kiss-cam clip went globally viral on July 16; the CEO caught in it resigned on July 19, the month's unlikely governance parable.
The keys outlive the patch
ToolShell became the reference case for a lesson the industry keeps having to relearn: patching a flaw does not evict an attacker who already stole your keys, and edge software you run yourself is a liability you own alone. Security teams spent months after July 2025 rotating machine keys and hunting for the forged-token persistence ToolShell left behind — the same "assume they're still inside" posture that October's F5 breach would demand at even larger scale. And July's quieter thread proved the more durable one: the ShinyHunters Salesforce campaign that hit Qantas and Allianz was the same current that ran through August's Salesloft token heist and, a year on, the platform raids our current editions cover weekly. The help desk, it turned out, was the front line all along.