Sunday, 7 September 2025
29 C
Singapore
27 C
Thailand
19.1 C
Indonesia
28.1 C
Philippines

Microsoft SharePoint servers face cyberattacks due to a critical security flaw

A zero-day flaw in Microsoft SharePoint is under active attack, putting thousands of on-premises servers at global businesses at risk.

Microsoft SharePoint servers used by companies and government agencies worldwide are under threat following the discovery of a major zero-day vulnerability. The flaw, which affects on-premises versions of the software, is currently being exploited by hackers to gain unauthorised access and impersonate users or services.

The issue was brought to light after cybersecurity experts observed active attacks exploiting the flaw. Microsoft acknowledged the vulnerability in an alert issued on 20 July and confirmed that it is working to patch affected systems. While cloud-based versions of SharePoint remain unaffected, organisations relying on local servers are urged to take immediate precautions.

Serious vulnerability exposes servers to data theft

The vulnerability was first identified by researchers at Dutch cybersecurity firm Eye Security on 18 July. According to their findings, the exploit allows attackers to steal authentication keys, which remain valid even after the server is restarted or updated. This means that compromised systems could still be at risk even after being patched unless specific steps are taken to remove the stolen credentials.

The exploit allows hackers to infiltrate SharePoint servers and then pivot to other connected services commonly used within organisations, such as Microsoft Outlook, Teams, and OneDrive. Through these systems, attackers can potentially harvest passwords, extract confidential data, and move laterally through networks.

Experts believe the vulnerability stems from a combination of two separate bugs, which were demonstrated at the Pwn2Own hacking competition in May. When used together, these flaws provide unauthenticated access to SharePoint servers—an especially dangerous capability for malicious actors.

Microsoft issues patches as global impact unfolds

Microsoft has released updates that offer full protection for SharePoint Server 2019 and SharePoint Subscription Edition. However, the company is still in the process of developing a fix for SharePoint Server 2016. In the meantime, administrators are advised to implement available workarounds and monitor their systems for signs of compromise.

The US Cybersecurity and Infrastructure Security Agency (CISA) is currently assessing the full scope and consequences of the attacks. CISA recommends that any server suspected of being compromised be disconnected from the internet until a complete patch is deployed and implemented.

According to a report by The Washington Post, the exploit has already been used to target various entities, including federal and state agencies in the US, academic institutions, energy sector firms, and a telecommunications company in Asia. The publication cited state officials and private cybersecurity researchers familiar with the matter.

Urgent action is needed to contain the threat

The incident highlights the growing risks associated with on-premises IT infrastructure, particularly in the face of increasingly sophisticated cyber threats. While Microsoft continues to address the issue, businesses are encouraged to remain vigilant and consider security audits of their systems.

Although no specific timeline has been provided for a complete resolution, organisations are expected to receive further guidance from Microsoft and cybersecurity agencies in the coming days.

Hot this week

Sony to showcase 007 First Light in upcoming State of Play

Sony will showcase IO Interactive’s 007 First Light in a 30-minute State of Play livestream on 3 September, offering a deep dive into gameplay.

Bose unveils second-generation QuietComfort Ultra headphones with lossless USB-C support

Bose launches its new QuietComfort Ultra headphones with USB-C lossless audio, longer battery life, and enhanced noise cancellation.

Singapore Polytechnic partners ESGpedia to strengthen sustainability efforts for local businesses

Singapore Polytechnic and ESGpedia partner to help Singapore businesses cut emissions, boost energy efficiency, and support the Green Plan 2030.

Apple may drop physical SIM cards for iPhone 17 and introduce a redesigned case

Apple is set to launch the iPhone 17 on 9 September, with rumours of eSIM-only models and a redesigned clear case with MagSafe.

Meta improves threaded posts on Threads with clearer design

Meta is updating Threads with clearer thread labels, numbered posts, and new layout tools to improve user experience.

OpenAI to launch job platform and AI certification scheme

OpenAI will launch an AI job platform and certification scheme to help employers find talent and upskill job seekers.

Meta improves threaded posts on Threads with clearer design

Meta is updating Threads with clearer thread labels, numbered posts, and new layout tools to improve user experience.

US court rules Google can keep Apple deal but must share search data with rivals

A US court ruled Google can keep its Apple deal but must share search data with rivals, marking a key antitrust decision.

ECOVACS unveils DEEBOT X11 with PowerBoost and expands service robot portfolio at IFA 2025

Ecovacs launches DEEBOT X11 with PowerBoost and expands its service robot lineup with ULTRAMARINE at IFA 2025.

Related Articles

Popular Categories