Global Cyberattack Exploits Microsoft SharePoint Flaw, Hits Governments and Businesses Worldwide
Hackers have exploited a significant security flaw in Microsoft's server software, targeting government agencies and businesses globally. This breach has affected U.S. federal and state agencies, universities, energy firms, and an Asian telecom company, as reported by state officials and private researchers.
The U.S., Canada, and Australia are investigating the compromise of SharePoint servers. These servers are crucial for document sharing and management. Experts warn that tens of thousands of these servers are at risk. Microsoft has yet to release a patch for this flaw.

Microsoft's Ongoing Cybersecurity Challenges
This "zero-day" attack is another cybersecurity issue for Microsoft. Last year, a panel criticized the company for lapses that allowed a 2023 Chinese hack of U.S. government emails, including those of then-Commerce Secretary Gina Raimondo.
The recent attack affects only on-premises servers within organizations, not cloud-based ones like Microsoft 365. Initially advising users to modify or disconnect SharePoint server programs from the internet, Microsoft released a patch for one software version on Sunday evening. However, two other versions remain vulnerable as the company continues to develop a patch.
Global Impact and Investigation Efforts
"Anybody who's got a hosted SharePoint server has got a problem," stated Adam Meyers from CrowdStrike, highlighting the vulnerability's significance. The FBI acknowledged awareness of the issue and is collaborating with federal and private sector partners.
The identity of the hackers or their ultimate goal remains unclear. A private research firm discovered hackers targeting servers in China and an eastern U.S. state legislature. Eye Security tracked over 50 breaches, including at an energy company in a large state and several European government agencies.
Confidentiality Agreements Limit Disclosure
At least two U.S. federal agencies have experienced server breaches according to researchers. However, confidentiality agreements prevent them from disclosing specific targets.
This incident underscores the ongoing challenges in cybersecurity faced by major companies like Microsoft and highlights the need for robust security measures to protect sensitive information across various sectors worldwide.


Click it and Unblock the Notifications








