Your Digital Life Is Under Attack: What Happened in June and July 2025 and What You Need to Know

June and July 2025 brought actively exploited browser flaws, known risks affecting phones and routers, and urgent SharePoint Server patches. Here is who was affected and what action made sense.

A blue digital shield deflecting red cyberattack lines

The most useful security news is not the headline. It is knowing whether the warning affects you and what to do next. In June and July 2025, some alerts were for everyday devices while one of the most serious incidents was limited to organisations running SharePoint Server on their own infrastructure.

The short version: Update browsers, phones and routers when fixes are available. If your organisation runs on-premises SharePoint Server, the July alert required immediate patching, key rotation and investigation. SharePoint Online in Microsoft 365 was not affected.

June: Chrome flaws were already being exploited

Google released Chrome updates for two high-severity V8 vulnerabilities during June. CVE-2025-5419 was addressed in the June 2 desktop release, and CVE-2025-6554 was addressed on June 30. Google said exploits existed in the wild for both issues.

Chrome normally updates itself, but the protection does not take effect until the browser is restarted. That small detail is easy to miss when a browser remains open for days.

  • Open Chrome's menu and choose Help, then About Google Chrome
  • Allow the update to finish and restart the browser
  • Repeat the check on every computer you regularly use
  • Update other Chromium-based browsers through their own update pages

June also showed why device updates matter

On June 16, CISA added an Apple-products vulnerability and a TP-Link router command-injection vulnerability to its Known Exploited Vulnerabilities catalogue. The notice was aimed at organisations, but the practical message also applies at home: phones, computers and routers need supported software and current vendor updates.

For phones and computers

Install operating-system and browser updates from the device's normal settings.

For home routers

Check the manufacturer's support page, install current firmware and replace equipment that no longer receives security fixes.

For work devices

Follow the organisation's update process rather than installing software from an email or pop-up.

July: the SharePoint warning was serious but specific

Microsoft reported active attacks against on-premises SharePoint Server and released updates for supported versions. The vulnerabilities included CVE-2025-53770 and CVE-2025-53771. Microsoft stated clearly that SharePoint Online in Microsoft 365 was not affected.

Patching was only the first step for exposed servers. Microsoft also advised organisations to rotate SharePoint Server ASP.NET machine keys, restart IIS, enable AMSI with suitable antivirus protection and investigate for signs of compromise.

Your situationRecommended actionDo not assume
You use SharePoint Online in Microsoft 365Confirm the service is SharePoint Online and keep normal account protections in place.That the on-premises server alert applied directly to the cloud service.
Your organisation runs SharePoint Server 2016, 2019 or Subscription EditionApply Microsoft's latest security updates, rotate machine keys, restart IIS and follow the official hunting guidance.That installing a patch alone removes access an attacker may already have gained.
You are unsure which version is in useAsk the IT owner or provider whether the service is online or self-hosted.That a familiar Microsoft 365 sign-in page proves how the service is hosted.

A simple response plan

Update what you use

Restart browsers after updates and install supported operating-system and router firmware releases.

Protect important accounts

Use a different password for every important account and turn on multi-factor authentication where it is available.

Check the exact product

Match every alert to the product, version and hosting model actually in use before taking action.

Use the official instructions

Follow the vendor's advisory for patches and recovery steps, especially when active exploitation is reported.

Security alerts become manageable when you separate them by audience. Browser and device updates mattered to almost everyone. The SharePoint incident demanded urgent technical work, but only from organisations running affected on-premises servers.

Found this useful?Share it with someone.
LinkedInXBluesky

Need more practical IT guides?

Explore step-by-step tutorials, expert insights, and actionable guidance to help you work smarter, stay secure, and solve real problems.

Browse More Articles