Close Menu
  • Home
  • Aerospace & Defense
    • Automation & Process Control
      • Automotive & Transportation
  • Banking & Finance
    • Chemicals & Materials
    • Consumer Goods & Services
  • Economy
    • Electronics & Semiconductor
  • Energy & Resources
    • Food & Beverage
    • Hospitality & Tourism
    • Information Technology
  • Agriculture
What's Hot

Will Zohran Mamdani help or hurt New York’s economy? | Politics News

Pack Expo Las Vegas celebrates 30 years of innovation

The platform allows machine learning to be more transparent and accessible

Facebook X (Twitter) Instagram
USA Business Watch – Insightful News on Economy, Finance, Politics & Industry
  • Home
  • Aerospace & Defense
    • Automation & Process Control
      • Automotive & Transportation
  • Banking & Finance
    • Chemicals & Materials
    • Consumer Goods & Services
  • Economy
    • Electronics & Semiconductor
  • Energy & Resources
    • Food & Beverage
    • Hospitality & Tourism
    • Information Technology
  • Agriculture
  • Home
  • About Us
  • Advertise With Us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
USA Business Watch – Insightful News on Economy, Finance, Politics & Industry
Home » New zero-day bug in Microsoft SharePoint is under widespread attack
Information Technology

New zero-day bug in Microsoft SharePoint is under widespread attack

ThefuturedatainsightsBy ThefuturedatainsightsJuly 21, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


US federal government and cybersecurity researchers say a newly discovered security bug found in Microsoft’s SharePoint is under attack.

The US cybersecurity agency CISA issued an alarm this weekend that hackers are actively using bugs. Microsoft has yet to provide patches for all affected SharePoint versions, and customers around the world can barely defend against ongoing intrusions.

Microsoft said the bug, officially known as CVE-2025-53771, affects the version of SharePoint that companies configure and manage on their own servers. SharePoint companies can store, share and manage internal files.

Microsoft said it is working on security fixes to prevent hackers from exploiting vulnerabilities. A flaw called “zero-day” affects older software versions, such as SharePoint Server 2016, because the vendor was not given time to patch the bug before it was recognized.

It is still unclear how many servers are at risk so far, but it is possible that thousands to medium-sized companies that rely on software are being affected. Several US federal agencies, universities and energy companies have already been violated by the attack, according to the Washington Post.

Ie’s Security, which first revealed the bug on Saturday, said it had discovered “dozens” of Microsoft SharePoint servers that were actively exploited online at the time of publication. A bug can, if exploited, allow hackers to steal private digital keys from SharePoint servers without the need for credentials to log in. Hackers can plant malware remotely and access files and data stored inside. Eye Security warned that SharePoint could connect with other apps like Outlook, Teams, OneDrive, allowing further network compromises and data theft.

According to Eye Security, the bug involves theft of digital keys because it requires both affected customers to impersonate a legitimate request on the server, performing additional steps to patch the bug and rotate the digital key, and performing additional steps to prevent hackers from reconfiguring the server.

CISA and others are urging customers to “take immediate and recommended actions.” In the absence of patches or mitigation, customers should consider disconnecting systems that are potentially affected from the Internet.

If you have SharePoint [on-premise] In an email to TechCrunch, Michael Sikorski, head of Threat Intelligence Division Unit 42 at Palo Alto Networks, said:

And while it’s still unknown who is running the attacks on SharePoint servers, it’s the latest in a series of cyberattacks targeting Microsoft customers in recent years.

In 2021, a Chinese-backed hacking group called Hafnium was caught using a vulnerability found in self-hosted Microsoft Exchange mail servers, allowing for mass suppression and delamination of email and contact data from businesses around the world. According to a recent Department of Justice indictment, hackers have breached more than 60,000 servers.

Two years later, Microsoft directly checked the cyberattacks on cloud systems, allowing Chinese hackers to steal sensitive email signature keys that allow the company to access both consumer and enterprise email accounts.

Microsoft has also reported repeated intrusions from hackers related to the Russian government.

Do you know more about SharePoint cyberattacks? Are you an affected customer? Please contact this reporter securely via a message encrypted with Zackwhittaker.1337.



Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLVMH backed L Catterton acquires 20% stake in FlexJet
Next Article Scalable transaccelerators enable device execution for large language models
Thefuturedatainsights
  • Website

Related Posts

Figma’s Dylan Field will win around $60 million in IPO.

July 21, 2025

Why Kurtken focused on industrial robots from last mile delivery

July 21, 2025

Figma is about to raise about $1 billion when it launches an IPO roadshow

July 21, 2025
Leave A Reply Cancel Reply

Latest Posts

Drug Mercedes driver crashed tractor into the house, court heard

NFU Cymru to PM: Don’t let tax reform destroy family farms

Video: 6 hectares of lost crop following the Hampshire Farm fire

Dairy sector wins as anti-farm ads pulled out of cinemas

Latest Posts

10 Things to Do on the Right Path for Stocks as Another Tariff Deadline approaches

July 21, 2025

Why Delta and United are pulling away from airline packs

July 18, 2025

Saab shares 12% pop in profit beats amid the EU, NATO defence scattering

July 18, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • Will Zohran Mamdani help or hurt New York’s economy? | Politics News
  • Pack Expo Las Vegas celebrates 30 years of innovation
  • The platform allows machine learning to be more transparent and accessible
  • Figma’s Dylan Field will win around $60 million in IPO.
  • Orange juice importers say Brazilian tariffs will raise prices for American consumers

Recent Comments

No comments to show.

Welcome to USA Business Watch – your trusted source for real-time insights, in-depth analysis, and industry trends across the American and global business landscape.

At USABusinessWatch.com, we aim to inform decision-makers, professionals, entrepreneurs, and curious minds with credible news and expert commentary across key sectors that shape the economy and society.

Facebook X (Twitter) Instagram Pinterest YouTube

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Archives

  • July 2025
  • June 2025
  • March 2022
  • January 2021

Categories

  • Aerospace & Defense
  • Agriculture
  • Automation & Process Control
  • Automotive & Transportation
  • Banking & Finance
  • Chemicals & Materials
  • Consumer Goods & Services
  • Economy
  • Economy
  • Electronics & Semiconductor
  • Energy & Resources
  • Food & Beverage
  • Hospitality & Tourism
  • Information Technology
  • Political
Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 usabusinesswatch. Designed by usabusinesswatch.

Type above and press Enter to search. Press Esc to cancel.