Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

ToolShell, Patch Bypass, and the AI That Might Have Seen It Coming

NDC Conferences via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore a comprehensive technical analysis of the ToolShell SharePoint vulnerability chain (CVE-2025-49704 and CVE-2025-49706) in this 47-minute conference talk from NDC Manchester. Dive deep into the complete incident timeline, starting from the ZDI Pwn2Own contest discovery in May 2025 through Microsoft's initial patch in July, the subsequent bypass exploitation by threat actors, and the emergency weekend patch that followed. Examine the vulnerable code paths and authentication bypass mechanisms that enabled remote code execution on SharePoint servers, while understanding why Microsoft's first patch proved ineffective. Trace the vulnerability's origins through historical SharePoint versions dating back to 2010 to understand its evolution. Watch live demonstrations showing how AI tools can assist in patch diffing and dynamic analysis to identify exploit code, and discover whether artificial intelligence could have detected the bypass when analyzing code changes alongside public research data. Learn about the official workarounds Microsoft recommended, how attackers could circumvent these protections in ASP.NET and IIS environments, and gain practical strategies for building more resilient mitigations against similar future attacks. Master the techniques for crafting detection signatures based on attack behavior patterns and understand how to leverage AI assistance for exploit detection and patch analysis in enterprise security contexts.

Syllabus

ToolShell, Patch Bypass, and the AI That Might Have Seen It Coming - Pedram Hayati & Soroush Dalili

Taught by

NDC Conferences

Reviews

Start your review of ToolShell, Patch Bypass, and the AI That Might Have Seen It Coming

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.