A vulnerabilidade CVE-2026-63520 no Microsoft SharePoint, que permite execução remota de código, está sendo explorada ativamente em ataques, conforme relatou a empresa de segurança cibernética Defused.
A vulnerabilidade CVE-2026-63520 no Microsoft SharePoint, que permite execução remota de código, está sendo explorada ativamente em ataques, conforme relatou a empresa de segurança cibernética Defused.
Em contexto
- Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
- Fonte: CISO Advisor
- Publicado: 28/08/2026
Continuar lendo na fonte original →
Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.
Why it matters
Every time I read a case like this I think the same thing: security is not bought, it is operated. You can own every tool on the market and remain exposed if nobody reviews the alerts, if patches get applied when there is time, or if the backup was never tested by actually restoring it.
I separate technical risk from business risk, because they do not always match. A critical vulnerability in an isolated system matters less than a medium one in the system that issues invoices. Prioritising by severity without looking at where the money is is an expensive way to work hard and protect little.
What usually goes wrong
What I see fail most is the backup. It is configured, it runs every night, nobody checks it. The day you need to restore, it turns out it had been failing silently for four months, or that everything was backed up except exactly what was needed. A backup never restored is an assumption.
What to watch
- What could be restored and how fast — a backup that was never tested does not count.
- How it was communicated to customers and regulators, which is where reputational cost is decided.
- Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
How I read this entry
I would use it for a conversation with the board, not with the technical team. The question you must be able to answer there is how long the business can operate without its systems and what each day of that outage costs. With that number, the security budget gets discussed differently.
The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Living through this in your own team?
Open the chat and tell me how you're handling it. I'm interested in comparing notes.