Hackers exploiting SharePoint zero-day seen targeting government agencies say researchers

Hackers target government agencies using SharePoint zero-day vulnerability
Photo: TechCrunch

Hackers target government agencies using SharePoint zero-day vulnerability

A newly discovered zero-day vulnerability in Microsoft SharePoint has been exploited by hackers, primarily targeting government agencies, according to cybersecurity experts. The vulnerability was first reported by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and researchers from Censys, a cybersecurity firm, confirmed the exploitation is mainly directed at governmental bodies. The vulnerability specifically affects SharePoint servers installed on local networks, rather than cloud-based versions, making organizations with on-premise SharePoint installations particularly vulnerable. Experts indicate that the initial attacks were likely carried out by a government-affiliated advanced persistent threat group. While the exploitation was initially limited, researchers predict that the attack’s scope could expand as more hackers discover the flaw. Between 9,000 and 10,000 vulnerable SharePoint instances are reportedly accessible over the internet, with dozens already compromised. The risk of further breaches remains high, as Microsoft has yet to issue a full patch for the issue. Affected organizations are advised to apply the patch or disconnect their servers from the internet until the vulnerability is fully resolved.

Leave a Reply

Your email address will not be published. Required fields are marked *