Microsoft Warns of Ongoing Attacks on SharePoint Servers, Urges Immediate Security Updates

Microsoft Warns of Ongoing Attacks on SharePoint Servers, Urges Immediate Security Updates

Microsoft has issued a critical warning about “active attacks” targeting on-premises SharePoint servers used by government agencies and businesses for internal document sharing. The tech giant is urging organizations to immediately install security updates to protect against the threat, which does not affect cloud-based SharePoint Online in Microsoft 365.

The attacks exploit a previously unknown vulnerability, making it a “zero-day” exploit, according to The Washington Post, which first reported the incident. Security experts say the flaw puts tens of thousands of servers at risk globally.

Microsoft stated in its advisory that the flaw “allows an authorized attacker to perform spoofing over a network.” In such attacks, bad actors impersonate trusted individuals or systems to gain unauthorized access, potentially allowing them to manipulate operations or steal sensitive information.

“We’ve been coordinating closely with CISA, DOD Cyber Defense Command and key cybersecurity partners globally throughout our response,” a Microsoft spokesperson said, emphasizing that patches have been issued and that customers should apply them without delay.

The FBI confirmed on Sunday that it is aware of the breach and is actively working with federal agencies and private-sector partners, though it has not released additional information on the attackers or the scale of the breach.

According to The Washington Post, unknown threat actors exploited the flaw in recent days to target both U.S. and international entities, including government institutions and corporations.

Microsoft clarified that only on-premise versions of SharePoint are affected. SharePoint Online, part of the company’s Microsoft 365 suite, remains secure, as it operates on separate cloud infrastructure.

For organizations running SharePoint Server 2016 and 2019, Microsoft is developing further updates. In the meantime, the company advises that if customers cannot implement the recommended security measures, they should disconnect vulnerable servers from the internet to prevent exploitation.

The situation underscores the growing threat posed by zero-day vulnerabilities and highlights the importance of prompt patching and robust cybersecurity protocols in enterprise environments.

- Advertisement -

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles

error: Content is protected !!

Share your details to download the Cybersecurity Report 2025

Share your details to download the CISO Handbook 2025

Sign Up for CXO Digital Pulse Newsletters

Share your details to download the Research Report

Share your details to download the Coffee Table Book

Share your details to download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Fill your details to Watch