Home
News

Global Cyberattack Exploits Microsoft SharePoint Flaw, Hits Governments and Businesses Worldwide

Hackers have exploited a significant security flaw in Microsoft's server software, targeting government agencies and businesses globally. This breach has affected U.S. federal and state agencies, universities, energy firms, and an Asian telecom company, as reported by state officials and private researchers.

The U.S., Canada, and Australia are investigating the compromise of SharePoint servers. These servers are crucial for document sharing and management. Experts warn that tens of thousands of these servers are at risk. Microsoft has yet to release a patch for this flaw.

Global Cyberattack Exploits Microsoft SharePoint Flaw

Microsoft's Ongoing Cybersecurity Challenges

This "zero-day" attack is another cybersecurity issue for Microsoft. Last year, a panel criticized the company for lapses that allowed a 2023 Chinese hack of U.S. government emails, including those of then-Commerce Secretary Gina Raimondo.

The recent attack affects only on-premises servers within organizations, not cloud-based ones like Microsoft 365. Initially advising users to modify or disconnect SharePoint server programs from the internet, Microsoft released a patch for one software version on Sunday evening. However, two other versions remain vulnerable as the company continues to develop a patch.

Global Impact and Investigation Efforts

"Anybody who's got a hosted SharePoint server has got a problem," stated Adam Meyers from CrowdStrike, highlighting the vulnerability's significance. The FBI acknowledged awareness of the issue and is collaborating with federal and private sector partners.

The identity of the hackers or their ultimate goal remains unclear. A private research firm discovered hackers targeting servers in China and an eastern U.S. state legislature. Eye Security tracked over 50 breaches, including at an energy company in a large state and several European government agencies.

Confidentiality Agreements Limit Disclosure

At least two U.S. federal agencies have experienced server breaches according to researchers. However, confidentiality agreements prevent them from disclosing specific targets.

This incident underscores the ongoing challenges in cybersecurity faced by major companies like Microsoft and highlights the need for robust security measures to protect sensitive information across various sectors worldwide.

Via

Best Mobiles in India

Notifications
Settings
Clear Notifications
Notifications
Use the toggle to switch on notifications
  • Block for 8 hours
  • Block for 12 hours
  • Block for 24 hours
  • Don't block
Gender
Select your Gender
  • Male
  • Female
  • Others
Age
Select your Age Range
  • Under 18
  • 18 to 25
  • 26 to 35
  • 36 to 45
  • 45 to 55
  • 55+
X