Microsoft

Microsoft Server Software Comes Under Widespread Cyberattack

Breadcrumb Trail Links Home PMN Business Share this Story : Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Copy Link Email X Reddit Pinterest LinkedIn Tumblr Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the

Microsoft Rushes to Stop Hackers from Wreaking Global Havoc

Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Advertisement 2
Advertisement
Article content

Tens of thousands — if not hundreds of thousands — of businesses and institutions worldwide use SharePoint in some fashion to store and collaborate on documents. Microsoft said that attackers are specifically targeting clients running SharePoint servers from their own on-premise networks, as opposed to being hosted and managed by the tech firm. That could limit the impact to a subsection of customers.

Article content

A Microsoft spokesperson declined to comment beyond an earlier statement.

Article content

“It’s a dream for ransomware operators,” said Silas Cutler, a researcher at Michigan-based cybersecurity firm Censys. He estimated that more than 10,000 companies with SharePoint servers were at risk. The US had the largest number of such firms, followed by the Netherlands, the UK and Canada, he said. 

Article content

The breaches have drawn new scrutiny to Microsoft’s efforts to shore up its cybersecurity after a series of high-profile failures. The firm has hired executives from places like the US government and holds weekly meetings with senior executives to make its software more resilient. The company’s tech has been subject to several widespread and damaging hacks in recent years, and a 2024 US government report described the company’s security culture as in need of urgent reforms.

Article content

Story continues below

Article content

The Center for Internet Security, which operates a cybersecurity information sharing system for state and local governments in the US, found more than 1,100 servers that are at risk from the SharePoint vulnerability, said Randy Rose, the organization’s vice president of security operations and intelligence. Rose said more than 100 were likely hacked.

Article content

The Washington Post reported that the breach had affected US federal and state agencies, universities, energy companies and an Asian telecommunications company, citing state officials and private researchers.

Article content

Eye Security was the first to identify that attackers were actively exploiting the vulnerabilities in a wave of cyberattacks that began on Friday, said Vaisha Bernard, the company’s chief hacker and co-owner.

Article content

Eye Security said the vulnerability allows hackers to access SharePoint servers and steal keys that can let them impersonate users or services even after the server is patched. It said hackers can maintain access through backdoors or modified components that can survive updates and reboots of systems.

Article content

Story continues below

Article content

The SharePoint vulnerabilities, known as “ToolShell,” were first identified in May by researchers at a Berlin cybersecurity conference. In early July, Microsoft issued patches to fix the security holes, but hackers found another way in.

Article content

“There were ways around the patches,” which enabled hackers to break into SharePoint servers by tapping into similar vulnerabilities, said Bernard. “That allowed these attacks to happen.” The intrusions, he said, were not targeted and instead were aimed at compromising as many victims as possible. After scanning about 8,000 SharePoint servers, Bernard said he has so far identified at least 50 that were successfully compromised.

Article content

He declined to identify the identity of organizations that had been targeted, but said they included government agencies and private companies, including “bigger multinationals.” The victims were located in countries in North and South America, the EU, South Africa, and Australia, he added.

Article content
Article content

—With assistance from Lynn Doan, Cameron Fozi, Daniel Cancel, Aashna Shah, Jane Lanhee Lee and Patrick Howell O’Neill.

Article content

(Updates with additional information beginning in third paragraph.)

Article content

Comments
You must be logged in to join the discussion or read more comments.
Create an AccountSign in
Join the Conversation

Postmedia is committed to maintaining a lively but civil forum for discussion. Please keep comments relevant and respectful. Comments may take up to an hour to appear on the site. You will receive an email if there is a reply to your comment, an update to a thread you follow or if a user you follow comments. Visit our Community Guidelines for more information.

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Microsoft

Windows XP’s most famous pirated key wasn’t a hack. It was a leak

About a year ago, in a social media post, long-time Microsoft veteran Dave Plummer (who worked on Windows Task Manager) recounted the story of what’s now known as the most iconic Windows product key. We’re talking about FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8. This product key for Windows XP—which is now celebrating its 25th anniversary—made the rounds in the early

About a year ago, in a social media post, long-time Microsoft veteran Dave Plummer (who worked on Windows Task Manager) recounted the story of what’s now known as the most iconic Windows product key.

We’re talking about FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8. This product key for Windows XP—which is now celebrating its 25th anniversary—made the rounds in the early 2000s…
Read More

Continue Reading
Microsoft

GTA 6 Leaker Releases More Gameplay Videos Despite Rockstar Owner Take-Two’s Microsoft and Discord Subpoenas

UPDATE AUGUST 24, 2026: The GTA 6 leaker has continued to release new gameplay clips, and is even running a poll to decide which video to leak next despite Rockstar parent company Take-Two’s ongoing hunt for people responsible. A tenth leaked GTA 6 video was released last night, this time showing plane at night gameplay.

UPDATE AUGUST 24, 2026: The GTA 6 leaker has continued to release new gameplay clips, and is even running a poll to decide which video to leak next despite Rockstar parent company Take-Two’s ongoing hunt for people responsible.

A tenth leaked GTA 6 video was released last night, this time showing plane at night gameplay. There is no cutscene footage this time.

The watermarks are the same as those on the previous video, advertising the ‘CyberLeek’ token at the heart of the cryptocurrency scheme that is believed to be the motivating factor behind all this. Another watermark doubles down on the anti-all-digital future manifesto that formed part of the initial CyberLeek website. It reads: “They want to take your right to resell. The peaceful route got us nowhere. This was plotted by them for years. It is time to fight now or never.”

Meanwhile, CyberLeek has a new poll available on its website with a number of gameplay video choices people can vote on by sending tokens. People are currently spending hundreds of dollars’ worth of the token to vote.

This poll ends today, August 24, which suggests the leaker or leakers intend to continue to release gameplay videos even in the face of Take-Two’s subpoenas of Microsoft, Discord, and X / Twitter as part of the company’s hunt for identifying information.

We are now into the sixth consecutive day of CyberLeek releases in what has been one of the most remarkable video game leaks of all time. It is now just a few days until Rockstar’s official GTA 6 reveal, exclusive to Netflix for six hours.

UPDATE AUGUST 23, 2026: The GTA 6 leaks have stretched into a sixth consecutive day, as the person or group responsible shows no sign of slowing down even in the face of court action from Rockstar parent company Take-Two.

The latest leak is the ninth GTA 6 gameplay video to emerge this week from the ‘CyberLeek’ persona. It shows one of the two protagonists, Jason, driving to a gas station to cause havoc. There he steals a pickup truck from a conspiracy theorist. The video ends with another brief look at the same cutscene shown in the gameplay videos that were leaked yesterday.

And, as with all the leaked GTA 6 videos, this “gas” clip advertises the ‘CyberLeek’ token at the heart of the cryptocurrency scheme that is believed to be the motivating factor behind all this. A new watermark doubles down on the anti-all-digital future manifesto that formed part of the initial CyberLeek website. It reads: “They want to take your right to resell. The peaceful route got us nowhere. This was plotted by them for years. It is time to fight now or never.”

In other related news. Take-Two lawyers have issued a subpoena to X / Twitter to identify the person or persons behind three accounts that contain ‘CyberLeak’ within them. This subpoena follows two filed earlier this week requesting information from Microsoft and Discord.

ORIGINAL STORY AUGUST 22, 2026: The alleged GTA 6 leaker has released two further gameplay videos despite Rockstar owner Take-Two’s subpoenas requesting identifying information from Microsoft and Discord.

The ‘CyberLeek’ person or group released two new videos today, August 22, one showing more supercar gameplay and an armed robbery, the other strip club gameplay. The latter appears to taunt Take-Two and Rockstar by showing a snippet of a cutscene in which a character says they need to take “a leak.” This is the second cutscene to emerge this week, and there is growing concern that the leaker has access to a build of the game and may post significant story spoilers.

These new videos are the seventh and eighth to leak this week. And, like all the others, they advertise the ‘CyberLeek’ memecoin as part of what is widely considered to be a crypto scheme.

Every Detail in the GTA 6 Cover Art Explained

On August 20, Take-Two issued Digital Millennium Copyright Act (DMCA) subpoenas in a federal court requesting information from both Microsoft and Discord as part of its hunt for the leaker or leakers behind the recent spate of GTA 6 gameplay videos. Take-Two wants identifying information associated with user accounts that were members of a number of Discord servers, including one relating to Australian GTA content cr

Read More

Continue Reading
Microsoft

Microsoft and Valve sued, PlayStation’s first party downturn, and could a UK social media ban impact games? – Patch Notes #55

Plus: Atari acquires Hipster Whale and Mina the Hollower hits 300,000 sales…

Plus: Atari acquires Hipster Whale and Mina the Hollower hits 300,000 sales…
Read More

Continue Reading
Microsoft

Nvidia and Microsoft drop cryptic coordinates pointing to an ARM powered PC revolution at GTC Taipei 2026

This morning I woke to social media teasers from both Nvidia and Microsoft, which seen many on social media speculating about it’s meaning. The identical posts feature a simple message – a new era of PC is coming. This isn’t jsut a new generation of an existing architecture…

This morning I woke to social media teasers from both Nvidia and Microsoft, which seen many on social media speculating about it’s meaning. The identical posts feature a simple message – a new era of PC is coming. This isn’t jsut a new generation of an existing architecture…
Read More

Continue Reading