The most useful security news is not the headline. It is knowing whether the warning affects you and what to do next. In June and July 2025, some alerts were for everyday devices while one of the most serious incidents was limited to organisations running SharePoint Server on their own infrastructure.
The short version: Update browsers, phones and routers when fixes are available. If your organisation runs on-premises SharePoint Server, the July alert required immediate patching, key rotation and investigation. SharePoint Online in Microsoft 365 was not affected.
June: Chrome flaws were already being exploited
Google released Chrome updates for two high-severity V8 vulnerabilities during June. CVE-2025-5419 was addressed in the June 2 desktop release, and CVE-2025-6554 was addressed on June 30. Google said exploits existed in the wild for both issues.
Chrome normally updates itself, but the protection does not take effect until the browser is restarted. That small detail is easy to miss when a browser remains open for days.
- Open Chrome's menu and choose Help, then About Google Chrome
- Allow the update to finish and restart the browser
- Repeat the check on every computer you regularly use
- Update other Chromium-based browsers through their own update pages
June also showed why device updates matter
On June 16, CISA added an Apple-products vulnerability and a TP-Link router command-injection vulnerability to its Known Exploited Vulnerabilities catalogue. The notice was aimed at organisations, but the practical message also applies at home: phones, computers and routers need supported software and current vendor updates.
Install operating-system and browser updates from the device's normal settings.
Check the manufacturer's support page, install current firmware and replace equipment that no longer receives security fixes.
Follow the organisation's update process rather than installing software from an email or pop-up.
July: the SharePoint warning was serious but specific
Microsoft reported active attacks against on-premises SharePoint Server and released updates for supported versions. The vulnerabilities included CVE-2025-53770 and CVE-2025-53771. Microsoft stated clearly that SharePoint Online in Microsoft 365 was not affected.
Patching was only the first step for exposed servers. Microsoft also advised organisations to rotate SharePoint Server ASP.NET machine keys, restart IIS, enable AMSI with suitable antivirus protection and investigate for signs of compromise.
A simple response plan
Restart browsers after updates and install supported operating-system and router firmware releases.
Use a different password for every important account and turn on multi-factor authentication where it is available.
Match every alert to the product, version and hosting model actually in use before taking action.
Follow the vendor's advisory for patches and recovery steps, especially when active exploitation is reported.
Security alerts become manageable when you separate them by audience. Browser and device updates mattered to almost everyone. The SharePoint incident demanded urgent technical work, but only from organisations running affected on-premises servers.

