Microsoft hit with SharePoint attack — one version still vulnerable

Microsoft hit with SharePoint attack — one version still vulnerable


A Microsoft store in New York, US, on Friday, Oct. 25, 2024. 

Jeenah Moon | Bloomberg | Getty Images

Microsoft has warned of “active attacks” targeting its SharePoint collaboration software, with security researchers noting that organizations worldwide stand to be affected by the breach.

The Cybersecurity and Infrastructure Security Agency said Sunday in a release that the vulnerability provides unauthenticated access to systems and full access to SharePoint content, enabling bad actors to execute code over the network.

CISA said that while the scope and impact of the attack continue to be assessed, the agency warned that it “poses a risk to organizations.”

Microsoft late Sunday issued fixes for customers to apply to two versions of the SharePoint software. Another 2016 version remains vulnerable and the company said it is working to develop a patch.

Researchers at Palo Alto Networks said the hack likely reached thousands of organizations globally.

“The exploits are real, in-the-wild and pose a serious threat,” they added.

In an alert on Saturday, Microsoft said the attack applies only to on-premises SharePoint servers, not those in the cloud like Microsoft 365. SharePoint software is commonly used by global businesses and organizations to store and collaborate on documents.

The vulnerability is especially concerning because it allows hackers to impersonate users or services even after the SharePoint server is patched, according to researchers at European cybersecurity firm Eye Security, which said it first identified the flaw.

SharePoint servers often connect to other Microsoft services such as Outlook and Teams, meaning such a breach can “quickly” lead to data theft and password harvesting, Eye Security researchers said.

Separately, Alaska Airlines briefly halted its ground operations for about three hours on Sunday due to an IT outage. It lifted the ground stop at roughly 2 a.m. EST, the carrier said in a statement.

It was unclear whether the outage was related to the SharePoint attack.



Source

Gen Z favorite toymaker Jellycat doubles annual profit in adult-fueled toy craze
World

Gen Z favorite toymaker Jellycat doubles annual profit in adult-fueled toy craze

Guests browse Jellycat products at Nordstrom Michigan Avenue on September 30, 2025 in Chicago, Illinois. Jeff Schear | Getty Images Entertainment | Getty Images British toybrand Jellycat, loved by Gen Z globally, more than doubled its profit in 2024 on the back of a “kidult” driven craze for toys as more adults turn to soft […]

Read More
The Trump crypto firm is planning expansion, from tokenized commodities to debit cards
World

The Trump crypto firm is planning expansion, from tokenized commodities to debit cards

Donald Trump Jr., co-founder of World Liberty Financial, during at the Token2049 conference in Singapore, on Wednesday, Oct. 1, 2025. Bloomberg | Bloomberg | Getty Images SINGAPORE — World Liberty Financial, a crypto venture linked to U.S. President Donald Trump, is planning to launch new products, including a debit card and tokenized commodity assets, as […]

Read More
Private payrolls declined in September by 32,000 in key ADP report coming amid shutdown data blackout
World

Private payrolls declined in September by 32,000 in key ADP report coming amid shutdown data blackout

Private payrolls saw their biggest decline in two-and-a-half years during September, a further sign of labor market weakening that compounds the data blackout accompanying the U.S. government shutdown. Companies shed a seasonally adjusted 32,000 jobs during the month, the biggest slide since March 2023, payrolls processing firm ADP reported Wednesday. Economists surveyed by Dow Jones […]

Read More