Microsoft

Microsoft Server Software Comes Under Widespread Cyberattack

Breadcrumb Trail Links Home PMN Business Share this Story : Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Copy Link Email X Reddit Pinterest LinkedIn Tumblr Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the

Microsoft Rushes to Stop Hackers from Wreaking Global Havoc

Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Advertisement 2
Advertisement
Article content

Tens of thousands — if not hundreds of thousands — of businesses and institutions worldwide use SharePoint in some fashion to store and collaborate on documents. Microsoft said that attackers are specifically targeting clients running SharePoint servers from their own on-premise networks, as opposed to being hosted and managed by the tech firm. That could limit the impact to a subsection of customers.

Article content

A Microsoft spokesperson declined to comment beyond an earlier statement.

Article content

“It’s a dream for ransomware operators,” said Silas Cutler, a researcher at Michigan-based cybersecurity firm Censys. He estimated that more than 10,000 companies with SharePoint servers were at risk. The US had the largest number of such firms, followed by the Netherlands, the UK and Canada, he said. 

Article content

The breaches have drawn new scrutiny to Microsoft’s efforts to shore up its cybersecurity after a series of high-profile failures. The firm has hired executives from places like the US government and holds weekly meetings with senior executives to make its software more resilient. The company’s tech has been subject to several widespread and damaging hacks in recent years, and a 2024 US government report described the company’s security culture as in need of urgent reforms.

Article content

Story continues below

Article content

The Center for Internet Security, which operates a cybersecurity information sharing system for state and local governments in the US, found more than 1,100 servers that are at risk from the SharePoint vulnerability, said Randy Rose, the organization’s vice president of security operations and intelligence. Rose said more than 100 were likely hacked.

Article content

The Washington Post reported that the breach had affected US federal and state agencies, universities, energy companies and an Asian telecommunications company, citing state officials and private researchers.

Article content

Eye Security was the first to identify that attackers were actively exploiting the vulnerabilities in a wave of cyberattacks that began on Friday, said Vaisha Bernard, the company’s chief hacker and co-owner.

Article content

Eye Security said the vulnerability allows hackers to access SharePoint servers and steal keys that can let them impersonate users or services even after the server is patched. It said hackers can maintain access through backdoors or modified components that can survive updates and reboots of systems.

Article content

Story continues below

Article content

The SharePoint vulnerabilities, known as “ToolShell,” were first identified in May by researchers at a Berlin cybersecurity conference. In early July, Microsoft issued patches to fix the security holes, but hackers found another way in.

Article content

“There were ways around the patches,” which enabled hackers to break into SharePoint servers by tapping into similar vulnerabilities, said Bernard. “That allowed these attacks to happen.” The intrusions, he said, were not targeted and instead were aimed at compromising as many victims as possible. After scanning about 8,000 SharePoint servers, Bernard said he has so far identified at least 50 that were successfully compromised.

Article content

He declined to identify the identity of organizations that had been targeted, but said they included government agencies and private companies, including “bigger multinationals.” The victims were located in countries in North and South America, the EU, South Africa, and Australia, he added.

Article content
Article content

—With assistance from Lynn Doan, Cameron Fozi, Daniel Cancel, Aashna Shah, Jane Lanhee Lee and Patrick Howell O’Neill.

Article content

(Updates with additional information beginning in third paragraph.)

Article content

Comments
You must be logged in to join the discussion or read more comments.
Create an AccountSign in
Join the Conversation

Postmedia is committed to maintaining a lively but civil forum for discussion. Please keep comments relevant and respectful. Comments may take up to an hour to appear on the site. You will receive an email if there is a reply to your comment, an update to a thread you follow or if a user you follow comments. Visit our Community Guidelines for more information.

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Microsoft

Arkane Founder: ‘I Think Game Pass is Unsustainable’

The founder and former president of Arkane Studios Raphaël Colantonio, who left in 2019, took to social media weighing on the huge Microsoft and Xbox layoffs. “Why is no-one talking about the elephant in the room? Cough cough (Gamepass),” said Colantonio (spotted by VideoGamesChronicle). He added…

The founder and former president of Arkane Studios Raphaël Colantonio, who left in 2019, took to social media weighing on the huge Microsoft and Xbox layoffs.
“Why is no-one talking about the elephant in the room? Cough cough (Gamepass),” said Colantonio (spotted by VideoGamesChronicle).
He added…
Read More

Continue Reading
Microsoft

In the Wake of Xbox Layoffs, Founder of Dishonored and Prey Dev Arkane Slams Game Pass: ‘Why Is No-One Talking About the Elephant in the Room?’

Hot on the heels of the layoffs that have swept through Xbox, the founder of Microsoft-owned Arkane Studios has hit out at Game Pass, whose subscription model he called “unsustainable.” Raphael Colantonio, who founded the Dishonored and Prey developer and served as its president before leaving in 2017 to start Weird West maker WolfEye Studios

Hot on the heels of the layoffs that have swept through Xbox, the founder of Microsoft-owned Arkane Studios has hit out at Game Pass, whose subscription model he called “unsustainable.”

Raphael Colantonio, who founded the Dishonored and Prey developer and served as its president before leaving in 2017 to start Weird West maker WolfEye Studios, took to social media to ask: “Why is no-one talking about the elephant in the room? Cough cough (Gamepass).”

When asked to expand on his thoughts on Game Pass, which Weird West launched straight into as a day one title in March 2022, Colantonio said: “I think Gamepass is an unsustainable model that has been increasingly damaging the industry for a decade, subsidized by MS’s ‘infinite money,’ but at some point reality has to hit. I don’t think GP can co-exist with other models, they’ll either kill everyone else, or give up.”

Colantonio’s comment sparked a vociferous debate about the pros and cons of Game Pass in industry terms as well as for the customer. Microsoft’s subscription service has been called many things over the years: the death of the video game industry; the savior of smaller developers who benefit greatly from payments made by Microsoft to secure their games; and everything in between. During the great Xbox FTC trial to decide the fate of Microsoft’s $69 billion aquisition of Call of Duty maker Activision Blizzard, then PlayStation boss Jim Ryan claimed that he had talked to “all the publishers” and that, unanimously, they all hated Game Pass “because it is value destructive.” He also said Microsoft “appears to be losing a lot of money on it.”

Back in 2021, Xbox boss Phil Spencer countered Game Pass doomsayers, saying: “I know there’s a lot of people that like to write [that] we’re burning cash right now for some future pot of gold at the end. No. Game Pass is very, very sustainable right now as it sits. And it continues to grow.”

That was four years ago. What about now, in the wake of cuts that have seen Rare’s Everwild, the Perfect Dark reboot, and an unannounced MMO in the works at developer behind The Elder Scrolls Online all canceled?

Colantonio’s comments were backed by a number of industry peers, including the former VP of biz dev at Epic Games. Michael Douse, publishing director at Baldur’s Gate 3 developer Larian, said that the biggest concern right now revolves around what happens when all that money runs out. This, Douse added, is “one of the main economic reasons people I know haven’t shifted to its business model. The infinite money thing never made any sense.”

(It’s worth noting that Baldur’s Gate 3 has so far not launched in Game Pass or PlayStation Plus.)

Colantonio then ridiculed Microsoft’s insistence that launching games into Game Pass did not impact sales, only to later admit the contrary.

Douse responded to to say he prefers the Sony way of doing things. Sony’s PlayStation Plus policy is to keep first-party games off the subscription service at launch, only adding them some time later. That’s why you won’t see this year’s Sony’s Ghost of Yotei launch straight into PS Plus, but you will see Call of Duty: Black Ops 7 as a day one Game Pass launch.

“The economics never made sense, but at the same

Read More

Continue Reading
Microsoft

Microsoft denies shutting down operations in China

Microsoft China denied it would cease operations in the country, after a screenshot of an internal email from Wicresoft, a Microsoft outsourcing partner, fueled speculation about a potential exit. On Monday, several employees of Wicresoft shared screenshots of layoff emails on social media. The email cites geopolitical tensions and shifts in the global business landscape

Microsoft China denied it would cease operations in the country, after a screenshot of an internal email from Wicresoft, a Microsoft outsourcing partner, fueled speculation about a potential exit. On Monday, several employees of Wicresoft shared screenshots of layoff emails on social media. The email cites geopolitical tensions and shifts in the global business landscape [……
Read More

Continue Reading
Microsoft

Fake Microsoft Office add-in tools push malware via SourceForge

Threat actors are abusing SourceForge to distribute fake Microsoft add-ins that install malware on victims’ computers to both mine and steal cryptocurrency. …

Threat actors are abusing SourceForge to distribute fake Microsoft add-ins that install malware on victims’ computers to both mine and steal cryptocurrency. …
Read More

Continue Reading