Thursday, 13 November 2025
26.4 C
Singapore
22.8 C
Thailand
21.5 C
Indonesia
28.4 C
Philippines

Microsoft SharePoint servers face cyberattacks due to a critical security flaw

A zero-day flaw in Microsoft SharePoint is under active attack, putting thousands of on-premises servers at global businesses at risk.

Microsoft SharePoint servers used by companies and government agencies worldwide are under threat following the discovery of a major zero-day vulnerability. The flaw, which affects on-premises versions of the software, is currently being exploited by hackers to gain unauthorised access and impersonate users or services.

The issue was brought to light after cybersecurity experts observed active attacks exploiting the flaw. Microsoft acknowledged the vulnerability in an alert issued on 20 July and confirmed that it is working to patch affected systems. While cloud-based versions of SharePoint remain unaffected, organisations relying on local servers are urged to take immediate precautions.

Serious vulnerability exposes servers to data theft

The vulnerability was first identified by researchers at Dutch cybersecurity firm Eye Security on 18 July. According to their findings, the exploit allows attackers to steal authentication keys, which remain valid even after the server is restarted or updated. This means that compromised systems could still be at risk even after being patched unless specific steps are taken to remove the stolen credentials.

The exploit allows hackers to infiltrate SharePoint servers and then pivot to other connected services commonly used within organisations, such as Microsoft Outlook, Teams, and OneDrive. Through these systems, attackers can potentially harvest passwords, extract confidential data, and move laterally through networks.

Experts believe the vulnerability stems from a combination of two separate bugs, which were demonstrated at the Pwn2Own hacking competition in May. When used together, these flaws provide unauthenticated access to SharePoint servers—an especially dangerous capability for malicious actors.

Microsoft issues patches as global impact unfolds

Microsoft has released updates that offer full protection for SharePoint Server 2019 and SharePoint Subscription Edition. However, the company is still in the process of developing a fix for SharePoint Server 2016. In the meantime, administrators are advised to implement available workarounds and monitor their systems for signs of compromise.

The US Cybersecurity and Infrastructure Security Agency (CISA) is currently assessing the full scope and consequences of the attacks. CISA recommends that any server suspected of being compromised be disconnected from the internet until a complete patch is deployed and implemented.

According to a report by The Washington Post, the exploit has already been used to target various entities, including federal and state agencies in the US, academic institutions, energy sector firms, and a telecommunications company in Asia. The publication cited state officials and private cybersecurity researchers familiar with the matter.

Urgent action is needed to contain the threat

The incident highlights the growing risks associated with on-premises IT infrastructure, particularly in the face of increasingly sophisticated cyber threats. While Microsoft continues to address the issue, businesses are encouraged to remain vigilant and consider security audits of their systems.

Although no specific timeline has been provided for a complete resolution, organisations are expected to receive further guidance from Microsoft and cybersecurity agencies in the coming days.

Hot this week

WhatsApp launches new app for Apple Watch

WhatsApp introduces its new Apple Watch app, bringing voice messages, reactions, media viewing, and full chat access to the wrist.

VAST Data signs US$1.17 billion partnership with CoreWeave to power next-generation AI

VAST Data signs US$1.17 billion deal with CoreWeave to expand AI infrastructure and power next-generation AI workloads.

Tenable reveals seven ChatGPT vulnerabilities that expose users to data theft and hijacking

Tenable identifies seven ChatGPT flaws exposing users to data theft and manipulation through indirect prompt injection attacks.

Synology marks 25 years with launch of next-generation enterprise solutions

Synology celebrates its 25th anniversary with new AI-powered enterprise storage and cybersecurity solutions for digital transformation.

H3 Zoom secures US$1.8 million in Series A funding led by JRE Ventures

H3 Zoom raises US$1.8M in Series A funding led by JRE Ventures to expand AI-powered infrastructure inspection across Asia.

GFTN unveils ALFIN, an AI-driven research engine for global finance

GFTN launches ALFIN, an AI-driven research platform offering verifiable, analyst-grade intelligence for finance professionals worldwide.

Meta opens AI showcase to the public in Singapore

Meta AI opens its first public showcase in Singapore, featuring interactive experiences and an exclusive preview of Ray-Ban Meta Glasses (Gen 2).

Nium joins Visa’s stablecoin settlement pilot to advance cross-border payments

Nium joins Visa’s stablecoin settlement pilot to modernise cross-border payments with faster, more secure blockchain-based settlements.

Visa launches Scan to Pay to accelerate QR payments across Asia Pacific

Visa introduces Scan to Pay across Asia Pacific, expanding QR payment acceptance and connecting millions of merchants and consumers through secure digital wallets.

Related Articles

Popular Categories