Microsoft

Microsoft Server Software Comes Under Widespread Cyberattack

Breadcrumb Trail Links Home PMN Business Share this Story : Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Copy Link Email X Reddit Pinterest LinkedIn Tumblr Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the

Microsoft Rushes to Stop Hackers from Wreaking Global Havoc

Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Advertisement 2
Advertisement
Article content

Tens of thousands — if not hundreds of thousands — of businesses and institutions worldwide use SharePoint in some fashion to store and collaborate on documents. Microsoft said that attackers are specifically targeting clients running SharePoint servers from their own on-premise networks, as opposed to being hosted and managed by the tech firm. That could limit the impact to a subsection of customers.

Article content

A Microsoft spokesperson declined to comment beyond an earlier statement.

Article content

“It’s a dream for ransomware operators,” said Silas Cutler, a researcher at Michigan-based cybersecurity firm Censys. He estimated that more than 10,000 companies with SharePoint servers were at risk. The US had the largest number of such firms, followed by the Netherlands, the UK and Canada, he said. 

Article content

The breaches have drawn new scrutiny to Microsoft’s efforts to shore up its cybersecurity after a series of high-profile failures. The firm has hired executives from places like the US government and holds weekly meetings with senior executives to make its software more resilient. The company’s tech has been subject to several widespread and damaging hacks in recent years, and a 2024 US government report described the company’s security culture as in need of urgent reforms.

Article content

Story continues below

Article content

The Center for Internet Security, which operates a cybersecurity information sharing system for state and local governments in the US, found more than 1,100 servers that are at risk from the SharePoint vulnerability, said Randy Rose, the organization’s vice president of security operations and intelligence. Rose said more than 100 were likely hacked.

Article content

The Washington Post reported that the breach had affected US federal and state agencies, universities, energy companies and an Asian telecommunications company, citing state officials and private researchers.

Article content

Eye Security was the first to identify that attackers were actively exploiting the vulnerabilities in a wave of cyberattacks that began on Friday, said Vaisha Bernard, the company’s chief hacker and co-owner.

Article content

Eye Security said the vulnerability allows hackers to access SharePoint servers and steal keys that can let them impersonate users or services even after the server is patched. It said hackers can maintain access through backdoors or modified components that can survive updates and reboots of systems.

Article content

Story continues below

Article content

The SharePoint vulnerabilities, known as “ToolShell,” were first identified in May by researchers at a Berlin cybersecurity conference. In early July, Microsoft issued patches to fix the security holes, but hackers found another way in.

Article content

“There were ways around the patches,” which enabled hackers to break into SharePoint servers by tapping into similar vulnerabilities, said Bernard. “That allowed these attacks to happen.” The intrusions, he said, were not targeted and instead were aimed at compromising as many victims as possible. After scanning about 8,000 SharePoint servers, Bernard said he has so far identified at least 50 that were successfully compromised.

Article content

He declined to identify the identity of organizations that had been targeted, but said they included government agencies and private companies, including “bigger multinationals.” The victims were located in countries in North and South America, the EU, South Africa, and Australia, he added.

Article content
Article content

—With assistance from Lynn Doan, Cameron Fozi, Daniel Cancel, Aashna Shah, Jane Lanhee Lee and Patrick Howell O’Neill.

Article content

(Updates with additional information beginning in third paragraph.)

Article content

Comments
You must be logged in to join the discussion or read more comments.
Create an AccountSign in
Join the Conversation

Postmedia is committed to maintaining a lively but civil forum for discussion. Please keep comments relevant and respectful. Comments may take up to an hour to appear on the site. You will receive an email if there is a reply to your comment, an update to a thread you follow or if a user you follow comments. Visit our Community Guidelines for more information.

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Microsoft

Xbox “has work to do”, but is “recommitting” to core fans following hardware revenue drop of 33% year-on-year

If you click on a link and make a purchase we may receive a small commission. Read our editorial policy. Home News Xbox “has work to do”, but is “recommitting” to core fans following hardware revenue drop of 33% year-on-year Player growth has “not yet met our ambition”. Image credit: Xbox News by Victoria Phillips

If you click on a link and make a purchase we may receive a small commission. Read our editorial policy.

Xbox “has work to do”, but is “recommitting” to core fans following hardware revenue drop of 33% year-on-year

Player growth has “not yet met our ambition”.


green Xbox logo on a dark background
Image credit: Xbox

Earlier today, Microsoft shared its earnings results Q3 FY2026, covering for the period between 1st January and 31st March. Microsoft’s revenue is up 18 percent, at $82.9bn, though gaming revenue fell seven percent. Xbox content and services also saw a drop of five percent year on year. Microsoft attributed this to “a prior year comparable that benefited from strong first-party performance”.

Meanwhile, Xbox hardware revenue dropped 33 percent. This follows a price rise for Xbox Series X/S consoles in the US towards the end of last year, the consoles’ second in six months. In November, Microsoft said this price increase was due to “changes in the macroeconomic environment”. Despite this, Microsoft CEO Satya Nadella said the company had “set new records for monthly Xbox active users in the quarter, as well as game streaming hours”.

A little teaser for Xbox’s Project Helix.Watch on YouTube

Writing on social media platform X, Microsoft’s newly-appointed Xbox boss Asha Sharma said “while we have made progress expanding the business and our margins

Read More

Continue Reading
Microsoft

IREN Doubles Down on AI Cloud Pivot as Bernstein Cuts Target but Keeps Top Pick Rating

IREN stayed Bernstein’s top AI-focused Bitcoin miner after a target cut to $100, as Microsoft-backed GPU expansion keeps its $3.7 billion cloud revenue target central to the stock story. The post IREN Doubles Down on AI Cloud Pivot as Bernstein Cuts Target but Keeps Top Pick Rating appeared first on Crypto News Australia…

IREN stayed Bernstein’s top AI-focused Bitcoin miner after a target cut to $100, as Microsoft-backed GPU expansion keeps its $3.7 billion cloud revenue target central to the stock story.
The post IREN Doubles Down on AI Cloud Pivot as Bernstein Cuts Target but Keeps Top Pick Rating appeared first on Crypto News Australia…
Read More

Continue Reading
Microsoft

Five Big Tech Earnings Could Decide Bitcoin’s Next Move This Week

Five of the largest US technology companies report quarterly results this week, and the outcomes could push Bitcoin (BTC) and broader crypto markets in either direction, given the unusually tight link between digital assets and Nasdaq equities. Microsoft, Alphabet, Meta, and Amazon release Q1 figures after the closing bell on Wednesday…

Five of the largest US technology companies report quarterly results this week, and the outcomes could push Bitcoin (BTC) and broader crypto markets in either direction, given the unusually tight link between digital assets and Nasdaq equities. Microsoft, Alphabet, Meta, and Amazon release Q1 figures after the closing bell on Wednesday…
Read More

Continue Reading
Microsoft

Microsoft-Backed Space and Time Just Launched a No-Code App Builder

Microsoft is not betting on crypto lightly. M12, Microsoft’s venture fund, led a $20 million investment in Space and Time back in 2022. Now that bet is paying off in a direction nobody saw coming. Space and Time just launched Dreamspace, a no-code AI app builder that lets anyone generate and deploy a fully functional

Microsoft is not betting on crypto lightly. M12, Microsoft’s venture fund, led a $20 million investment in Space and Time back in 2022. Now that bet is paying off in a direction nobody saw coming. Space and Time just launched Dreamspace, a no-code AI app builder that lets anyone generate and deploy a fully functional […]
The post Microsoft-Backed Space and Time Just Launched a No-Code App Builder appeared first on Altcoin Buzz…
Read More

Continue Reading