Hackers Exploit Vulnerability in Outdated SharePoint Versions as Microsoft Ends Support
A recent wave of cyberattacks has targeted older, on-premises versions of Microsoft’s SharePoint, with several organizations falling victim to data breaches. The vulnerability was discovered after a flawed patch, which left users exposed even if they had applied previous security updates. Hackers, including China-linked groups, have exploited the flaw to breach systems. Microsoft had already planned to phase out support for these older SharePoint versions, pushing users toward its cloud services. Notably, the United States National Nuclear Security Administration was affected, although the breach did not compromise sensitive data. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) advises disconnecting outdated versions of SharePoint from the internet. Microsoft has since issued a fix for the flawed patch, but the incident underscores the growing risks of continuing to use legacy software that lacks regular updates and support. The situation highlights the challenge faced by many organizations reluctant to upgrade to newer platforms, as legacy systems remain a potential target for hackers. Microsoft’s cloud service, M365, has been touted as a more secure alternative to the on-premises version, but legacy SharePoint remains in use by many.
