Sunday, 26 October 2025
31.7 C
Singapore
30.8 C
Thailand
28.3 C
Indonesia
28.5 C
Philippines

Microsoft SharePoint servers face cyberattacks due to a critical security flaw

A zero-day flaw in Microsoft SharePoint is under active attack, putting thousands of on-premises servers at global businesses at risk.

Microsoft SharePoint servers used by companies and government agencies worldwide are under threat following the discovery of a major zero-day vulnerability. The flaw, which affects on-premises versions of the software, is currently being exploited by hackers to gain unauthorised access and impersonate users or services.

The issue was brought to light after cybersecurity experts observed active attacks exploiting the flaw. Microsoft acknowledged the vulnerability in an alert issued on 20 July and confirmed that it is working to patch affected systems. While cloud-based versions of SharePoint remain unaffected, organisations relying on local servers are urged to take immediate precautions.

Serious vulnerability exposes servers to data theft

The vulnerability was first identified by researchers at Dutch cybersecurity firm Eye Security on 18 July. According to their findings, the exploit allows attackers to steal authentication keys, which remain valid even after the server is restarted or updated. This means that compromised systems could still be at risk even after being patched unless specific steps are taken to remove the stolen credentials.

The exploit allows hackers to infiltrate SharePoint servers and then pivot to other connected services commonly used within organisations, such as Microsoft Outlook, Teams, and OneDrive. Through these systems, attackers can potentially harvest passwords, extract confidential data, and move laterally through networks.

Experts believe the vulnerability stems from a combination of two separate bugs, which were demonstrated at the Pwn2Own hacking competition in May. When used together, these flaws provide unauthenticated access to SharePoint servers—an especially dangerous capability for malicious actors.

Microsoft issues patches as global impact unfolds

Microsoft has released updates that offer full protection for SharePoint Server 2019 and SharePoint Subscription Edition. However, the company is still in the process of developing a fix for SharePoint Server 2016. In the meantime, administrators are advised to implement available workarounds and monitor their systems for signs of compromise.

The US Cybersecurity and Infrastructure Security Agency (CISA) is currently assessing the full scope and consequences of the attacks. CISA recommends that any server suspected of being compromised be disconnected from the internet until a complete patch is deployed and implemented.

According to a report by The Washington Post, the exploit has already been used to target various entities, including federal and state agencies in the US, academic institutions, energy sector firms, and a telecommunications company in Asia. The publication cited state officials and private cybersecurity researchers familiar with the matter.

Urgent action is needed to contain the threat

The incident highlights the growing risks associated with on-premises IT infrastructure, particularly in the face of increasingly sophisticated cyber threats. While Microsoft continues to address the issue, businesses are encouraged to remain vigilant and consider security audits of their systems.

Although no specific timeline has been provided for a complete resolution, organisations are expected to receive further guidance from Microsoft and cybersecurity agencies in the coming days.

Hot this week

Chiang Mai University to join IBM-NUS research and innovation centre and IBM Quantum Network

Chiang Mai University joins IBM and NUS to advance AI and quantum research, aiming to strengthen innovation and digital skills across Southeast Asia.

Twitch CEO responds to streamer assault at TwitchCon 2025

Twitch CEO Dan Clancy responds to streamer Emiru’s assault at TwitchCon 2025 amid criticism over safety and Twitch’s handling of the incident.

Canon Singapore launches imageFORCE C5100 series to drive AI adoption in businesses

Canon Singapore launches the AI-powered imageFORCE C5100 series, helping businesses boost productivity and sustainability.

Leica launches new M-mount camera that ditches the rangefinder

Leica unveils the M EV1, its first M-series camera with an electronic viewfinder, marking a bold step beyond its iconic rangefinder design.

Deel launches new tools to simplify year-end planning and payroll

Deel unveils year-end upgrades featuring AI-driven tools to simplify payroll, compliance, and workforce planning for global teams.

Samsung One UI 8.5 may introduce a new notification prioritisation tool

Samsung’s upcoming One UI 8.5 update may include a new tool that prioritises important notifications to improve alert management.

Neato cloud shutdown leaves robot vacuums limited to manual operation

Neato’s cloud services are shutting down, leaving its robot vacuums without app control and limited to manual operation.

New Nomad Stratos Band blends titanium durability with everyday comfort

Nomad launches the Stratos Band, a hybrid Apple Watch band combining titanium and FKM rubber for durability and everyday comfort.

Red Hat: Building a secure foundation for hybrid cloud and AI in APAC

Red Hat Enterprise Linux 10 strengthens security and compliance for hybrid cloud and AI in APAC, helping enterprises navigate complex regulations.

Related Articles