Microsoft

Microsoft Server Software Comes Under Widespread Cyberattack

Breadcrumb Trail Links Home PMN Business Share this Story : Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Copy Link Email X Reddit Pinterest LinkedIn Tumblr Microsoft Rushes to Stop Hackers from Wreaking Global Havoc Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the

Microsoft Rushes to Stop Hackers from Wreaking Global Havoc

Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Article content

(Bloomberg) — Hackers exploited a security flaw in common Microsoft Corp. software to breach governments, businesses and other organizations across the globe and steal sensitive information, according to officials and cybersecurity researchers.

Article content

Microsoft over the weekend released a patch for the vulnerability in servers of the SharePoint document management software. The company said it was still working to roll out other fixes after warnings that hackers were targeting SharePoint clients, using the flaw to enter file systems and execute code.

Article content
Article content

Story continues below

Article content

Multiple different hackers are launching attacks through the Microsoft vulnerability, according to representatives of two cybersecurity firms, CrowdStrike Holdings, Inc. and Google’s Mandiant Consulting.

Article content
Article content

Hackers have already used the flaw to break into the systems of national governments in Europe and the Middle East, according to a person familiar with the matter. In the US, they’ve accessed government systems, including ones belonging to the US Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly, said the person, who spoke on condition that they not be identified discussing the sensitive information.

Article content

Representatives of the Department of Education and Rhode Island legislature didn’t respond to calls and emails seeking comment Monday. A Florida Department of Revenue spokesperson, Bethany Wester Cutillo, said in an email that the SharePoint vulnerability is being investigated “at multiple levels of government” but that the state agency “does not comment publicly on the software we use for operations.”

Article content

Story continues below

Article content

The hackers also breached the systems of a US-based health-care provider and targeted a public university in Southeast Asia, according to a report from a cybersecurity firm reviewed by Bloomberg News. The report doesn’t identify either entity by name, but says the hackers have attempted to breach SharePoint servers in countries including Brazil, Canada, Indonesia, Spain, South Africa, Switzerland, the UK and the US. The firm asked not to be named because of the sensitivity of the information. 

Article content

In some systems they’ve broken into, the hackers have stolen sign-in credentials, including usernames, passwords, hash codes and tokens, according to a person familiar with the matter, who also spoke on condition that they not be identified discussing the sensitive information.

Article content

“This is a high-severity, high-urgency threat,” said Michael Sikorski, chief technology officer and head of threat intelligence for Unit 42 at Palo Alto Networks Inc. 

Article content

“What makes this especially concerning is SharePoint’s deep integration with Microsoft’s platform, including their services like Office, Teams, OneDrive and Outlook, which has all the information valuable to an attacker,” he said. “A compromise doesn’t stay contained—it opens the door to the entire network.” 

Advertisement 2
Advertisement
Article content

Tens of thousands — if not hundreds of thousands — of businesses and institutions worldwide use SharePoint in some fashion to store and collaborate on documents. Microsoft said that attackers are specifically targeting clients running SharePoint servers from their own on-premise networks, as opposed to being hosted and managed by the tech firm. That could limit the impact to a subsection of customers.

Article content

A Microsoft spokesperson declined to comment beyond an earlier statement.

Article content

“It’s a dream for ransomware operators,” said Silas Cutler, a researcher at Michigan-based cybersecurity firm Censys. He estimated that more than 10,000 companies with SharePoint servers were at risk. The US had the largest number of such firms, followed by the Netherlands, the UK and Canada, he said. 

Article content

The breaches have drawn new scrutiny to Microsoft’s efforts to shore up its cybersecurity after a series of high-profile failures. The firm has hired executives from places like the US government and holds weekly meetings with senior executives to make its software more resilient. The company’s tech has been subject to several widespread and damaging hacks in recent years, and a 2024 US government report described the company’s security culture as in need of urgent reforms.

Article content

Story continues below

Article content

The Center for Internet Security, which operates a cybersecurity information sharing system for state and local governments in the US, found more than 1,100 servers that are at risk from the SharePoint vulnerability, said Randy Rose, the organization’s vice president of security operations and intelligence. Rose said more than 100 were likely hacked.

Article content

The Washington Post reported that the breach had affected US federal and state agencies, universities, energy companies and an Asian telecommunications company, citing state officials and private researchers.

Article content

Eye Security was the first to identify that attackers were actively exploiting the vulnerabilities in a wave of cyberattacks that began on Friday, said Vaisha Bernard, the company’s chief hacker and co-owner.

Article content

Eye Security said the vulnerability allows hackers to access SharePoint servers and steal keys that can let them impersonate users or services even after the server is patched. It said hackers can maintain access through backdoors or modified components that can survive updates and reboots of systems.

Article content

Story continues below

Article content

The SharePoint vulnerabilities, known as “ToolShell,” were first identified in May by researchers at a Berlin cybersecurity conference. In early July, Microsoft issued patches to fix the security holes, but hackers found another way in.

Article content

“There were ways around the patches,” which enabled hackers to break into SharePoint servers by tapping into similar vulnerabilities, said Bernard. “That allowed these attacks to happen.” The intrusions, he said, were not targeted and instead were aimed at compromising as many victims as possible. After scanning about 8,000 SharePoint servers, Bernard said he has so far identified at least 50 that were successfully compromised.

Article content

He declined to identify the identity of organizations that had been targeted, but said they included government agencies and private companies, including “bigger multinationals.” The victims were located in countries in North and South America, the EU, South Africa, and Australia, he added.

Article content
Article content

—With assistance from Lynn Doan, Cameron Fozi, Daniel Cancel, Aashna Shah, Jane Lanhee Lee and Patrick Howell O’Neill.

Article content

(Updates with additional information beginning in third paragraph.)

Article content

Comments
You must be logged in to join the discussion or read more comments.
Create an AccountSign in
Join the Conversation

Postmedia is committed to maintaining a lively but civil forum for discussion. Please keep comments relevant and respectful. Comments may take up to an hour to appear on the site. You will receive an email if there is a reply to your comment, an update to a thread you follow or if a user you follow comments. Visit our Community Guidelines for more information.

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Microsoft

Xbox Boss Asha Sharma Announces Leadership Reshuffle in Bid to ‘Move Faster,’ Bringing in Former Microsoft AI Colleagues

UPDATE: Xbox boss Asha Sharma has confirmed that Microsoft has stopped development of Copilot on console. In a tweet, Sharma said Microsoft will retire features “that don’t align with where we’re headed.” Gaming Copilot, which was in beta, was designed as “your personal gaming sidekick with Xbox.” The idea was that players could ask for

UPDATE: Xbox boss Asha Sharma has confirmed that Microsoft has stopped development of Copilot on console.

In a tweet, Sharma said Microsoft will retire features “that don’t align with where we’re headed.”

Gaming Copilot, which was in beta, was designed as “your personal gaming sidekick with Xbox.” The idea was that players could ask for help anytime or anywhere while they were playing a game. “With in-game assistance, get unstuck, pass roadblocks, and level-up your gameplay,” Microsoft said. “The guide you want, when you want it. Brainstorm strategies and get tips or insights with personalized coaching.”

It would also provide users with gaming recommendations. Gaming Copilot is currently available in the Xbox mobile app, and on Game Bar for Windows 11, and on the ROG Xbox Ally handhelds.

“Xbox needs to move faster, deepen our connection with the community, and address friction for both players and developers,” Sharma said. “Today, we promoted leaders who helped build Xbox, while also bringing in new voices to help push us forward. This balance is important as we get the business back on track. As part of this shift, you’ll see us begin to retire features that don’t align with where we’re headed. We will begin winding down Copilot on mobile and will stop development of Copilot on console.”

ORIGINAL STORY: Newly-installed Xbox boss Asha Sharma has announced a major reshuffle of the company’s platform technology teams, as Microsoft’s gaming division seeks to rebuild its position and release Project Helix, its next-generation console.

In an internal memo shared with Xbox staff today, seen by IGN, Sharma stated that leadership change was needed to “begin building the capacity we need” to evolve the Xbox brand and “how we work.”

As part of the changes, Sharma is bringing four former colleagues from Microsoft’s CoreAI division, where she previously served, over to Xbox. IGN understands that Xbox’s previous stance on AI remains unchanged.

The 100 Best Xbox Games of All Time

“Right now, it is too hard to ship impact quickly,” Sharma wrote, adding: “we spend too much time inward instead of with the community; and we lack the capability we need in some key areas.”

For Xbox fans, likely the most widely-known name among the list of today’s changes is that of Jason Ronald, the Microsoft veteran with more than 20 years of experience building Xbox. Ronald has now been elevated to a position where he is accountable for Project Helix and the Xbox platform.

Elsewhere on the company’s hardware team, Roanne Sones, a corporate vice president for Xbox devices and ecosystem, will take a long-planned leave of absence later this year and return as an Xbox advisor.

CoreAI vice president of product Jared Palmer, will join Xbox’s platform-level content push “investing in the systems that make it easy to build, submit and scale high-quality games,” with a focus on “developer tooling, taste and infrastructure.” Tim Allen, another key CoreAI staff member, will join Xbox to lead experience design, in a role that merges “product design, design engineering, research, and creative with a fan-first focus.”

Jonathan McKay will become Xbox’s head of growth. Evan Chaki will run a new engineering group focused on removing repetitive work and simplifying development. Both are also moving over from Microsoft’s CoreAI division.

Other changes will see David Schloss, a former colleague of Sharma’s at Instacart, lead the Xbox subscription and cloud business. Kevin Gammill, a 20-year Microsoft veteran who has worked on the Xbox user experience, will meanwhile leave the company.

Tier List

Xbox Games Series Tier List

Xbox Games Series Tier List

 
 
 
 
 

While the quartet of additions to Xbox from CoreAI will likely raise eyebrows — as Sharma’s own move did earlier this year — the changes are believed to be positioned internally as simply about bringing in the best talent, with experience working in Microsoft’s AI division seen as just another part of the company.

The changes follow another bruising quarter for Microsoft’s gaming division. In the three months ending March 31, 2026, Microsoft’s Gaming revenue decreased 7%, Xbox content and services revenue decreased 5%, and Xbox hardware revenue (money made from the sale of Xbox consoles) declined 33%.

“While we have made progress expanding the business and our margins, player and revenue growth has not yet met our ambition,” Sharma wrote last week via a post on social media. “We know we have work to do to earn every player today and into the future.”

Last month brought a new mission statement from Sharma an

Read More

Continue Reading
Microsoft

Microsoft Edge stores your passwords in plaintext RAM… on purpose

If you tend to save your passwords in your browser, you need to be more careful. A security researcher from Norway has uncovered a serious vulnerability in Microsoft Edge that shows passwords are stored in memory as plaintext, as shown in this social media post. Any malicious user with local access could easily intercept all

If you tend to save your passwords in your browser, you need to be more careful. A security researcher from Norway has uncovered a serious vulnerability in Microsoft Edge that shows passwords are stored in memory as plaintext, as shown in this social media post.

Any malicious user with local access could easily intercept all your stored passwords…
Read More

Continue Reading
Microsoft

Xbox “has work to do”, but is “recommitting” to core fans following hardware revenue drop of 33% year-on-year

If you click on a link and make a purchase we may receive a small commission. Read our editorial policy. Home News Xbox “has work to do”, but is “recommitting” to core fans following hardware revenue drop of 33% year-on-year Player growth has “not yet met our ambition”. Image credit: Xbox News by Victoria Phillips

If you click on a link and make a purchase we may receive a small commission. Read our editorial policy.

Xbox “has work to do”, but is “recommitting” to core fans following hardware revenue drop of 33% year-on-year

Player growth has “not yet met our ambition”.


green Xbox logo on a dark background
Image credit: Xbox

Earlier today, Microsoft shared its earnings results Q3 FY2026, covering for the period between 1st January and 31st March. Microsoft’s revenue is up 18 percent, at $82.9bn, though gaming revenue fell seven percent. Xbox content and services also saw a drop of five percent year on year. Microsoft attributed this to “a prior year comparable that benefited from strong first-party performance”.

Meanwhile, Xbox hardware revenue dropped 33 percent. This follows a price rise for Xbox Series X/S consoles in the US towards the end of last year, the consoles’ second in six months. In November, Microsoft said this price increase was due to “changes in the macroeconomic environment”. Despite this, Microsoft CEO Satya Nadella said the company had “set new records for monthly Xbox active users in the quarter, as well as game streaming hours”.

A little teaser for Xbox’s Project Helix.Watch on YouTube

Writing on social media platform X, Microsoft’s newly-appointed Xbox boss Asha Sharma said “while we have made progress expanding the business and our margins

Read More

Continue Reading
Microsoft

IREN Doubles Down on AI Cloud Pivot as Bernstein Cuts Target but Keeps Top Pick Rating

IREN stayed Bernstein’s top AI-focused Bitcoin miner after a target cut to $100, as Microsoft-backed GPU expansion keeps its $3.7 billion cloud revenue target central to the stock story. The post IREN Doubles Down on AI Cloud Pivot as Bernstein Cuts Target but Keeps Top Pick Rating appeared first on Crypto News Australia…

IREN stayed Bernstein’s top AI-focused Bitcoin miner after a target cut to $100, as Microsoft-backed GPU expansion keeps its $3.7 billion cloud revenue target central to the stock story.
The post IREN Doubles Down on AI Cloud Pivot as Bernstein Cuts Target but Keeps Top Pick Rating appeared first on Crypto News Australia…
Read More

Continue Reading