Tuesday, 22 July 2025
28.2 C
Singapore
29.6 C
Thailand
20 C
Indonesia
28.8 C
Philippines

Microsoft SharePoint servers face cyberattacks due to a critical security flaw

A zero-day flaw in Microsoft SharePoint is under active attack, putting thousands of on-premises servers at global businesses at risk.

Microsoft SharePoint servers used by companies and government agencies worldwide are under threat following the discovery of a major zero-day vulnerability. The flaw, which affects on-premises versions of the software, is currently being exploited by hackers to gain unauthorised access and impersonate users or services.

The issue was brought to light after cybersecurity experts observed active attacks exploiting the flaw. Microsoft acknowledged the vulnerability in an alert issued on 20 July and confirmed that it is working to patch affected systems. While cloud-based versions of SharePoint remain unaffected, organisations relying on local servers are urged to take immediate precautions.

Serious vulnerability exposes servers to data theft

The vulnerability was first identified by researchers at Dutch cybersecurity firm Eye Security on 18 July. According to their findings, the exploit allows attackers to steal authentication keys, which remain valid even after the server is restarted or updated. This means that compromised systems could still be at risk even after being patched unless specific steps are taken to remove the stolen credentials.

The exploit allows hackers to infiltrate SharePoint servers and then pivot to other connected services commonly used within organisations, such as Microsoft Outlook, Teams, and OneDrive. Through these systems, attackers can potentially harvest passwords, extract confidential data, and move laterally through networks.

Experts believe the vulnerability stems from a combination of two separate bugs, which were demonstrated at the Pwn2Own hacking competition in May. When used together, these flaws provide unauthenticated access to SharePoint servers—an especially dangerous capability for malicious actors.

Microsoft issues patches as global impact unfolds

Microsoft has released updates that offer full protection for SharePoint Server 2019 and SharePoint Subscription Edition. However, the company is still in the process of developing a fix for SharePoint Server 2016. In the meantime, administrators are advised to implement available workarounds and monitor their systems for signs of compromise.

The US Cybersecurity and Infrastructure Security Agency (CISA) is currently assessing the full scope and consequences of the attacks. CISA recommends that any server suspected of being compromised be disconnected from the internet until a complete patch is deployed and implemented.

According to a report by The Washington Post, the exploit has already been used to target various entities, including federal and state agencies in the US, academic institutions, energy sector firms, and a telecommunications company in Asia. The publication cited state officials and private cybersecurity researchers familiar with the matter.

Urgent action is needed to contain the threat

The incident highlights the growing risks associated with on-premises IT infrastructure, particularly in the face of increasingly sophisticated cyber threats. While Microsoft continues to address the issue, businesses are encouraged to remain vigilant and consider security audits of their systems.

Although no specific timeline has been provided for a complete resolution, organisations are expected to receive further guidance from Microsoft and cybersecurity agencies in the coming days.

Hot this week

Garmin introduces Descent S1 buoy to enhance dive communication and safety

Garmin launches the Descent S1 Buoy in Singapore to improve diver tracking, messaging and safety through advanced sonar technology.

Salesforce expands Hyperforce services in Indonesia with local data residency

Salesforce brings local data residency and AI-driven services to Indonesia with the expansion of Hyperforce and new platform tools.

Samsung introduces new Smart Monitor range featuring first OLED M9 model

Samsung launches a new Smart Monitor range, featuring the first OLED M9 model and refreshed M8 and M7 models with AI and productivity upgrades.

SoftBank plans a billion AI agents to boost workers like ‘thousand-armed deities’

SoftBank aims to launch a billion self-replicating AI agents by year-end to boost productivity, but concerns about job displacement remain.

Confluent Cloud now listed under new AI category on AWS Marketplace

Confluent Cloud is now available in AWS Marketplace's AI Agents and Tools category, supporting real-time data access for AI applications.

WhatsApp replaces Windows native app with web-based version

Meta replaces WhatsApp’s Windows app with a web-based version, reducing performance and integration with Windows 11.

Fortune Brainstorm AI returns to Singapore as global leaders explore next-generation artificial intelligence

Fortune Brainstorm AI returns to Singapore on 22–23 July with top global leaders to explore scalable and responsible artificial intelligence.

Alibaba Cloud named a GenAI leader in Omdia’s latest Asia and Oceania report

Alibaba Cloud named GenAI leader in Omdia’s Asia & Oceania 2025 report, topping seven of nine categories for innovation and adoption.

Denodo introduces DeepQuery to boost enterprise AI with real-time, explainable insights

Denodo launches DeepQuery to enable explainable, real-time AI insights from enterprise data, now available in private preview.

Related Articles

Popular Categories