Microsoft, SharePoint
Digest more
The hackers behind the initial wave of attacks exploiting a zero-day in Microsoft SharePoint servers have so far primarily targeted government organizations, according to researchers and news reports.
Active SharePoint exploits since July 7 target governments and tech firms globally, risking key theft and persistent access.
A cyber-espionage campaign centred on vulnerable Microsoft software now involves the deployment of ransomware.
More information has emerged on the ToolShell SharePoint zero-day attacks, including impact, victims, and threat actors.
2d
Asianet Newsable on MSNUS Nuclear Weapons Agency Reportedly Hit In Microsoft ‘Zero-Day’ Breach — DOE Says Impact Was MinimalProviding additional updates on the breach, Microsoft said in a blog post on Tuesday that two Chinese nation-state operators, Linen Typhoon and Violet Typhoon, exploited vulnerabilities in the internet-facing SharePoint servers.
Microsoft is investigating whether a leak from its early alert system for cybersecurity companies allowed Chinese hackers to exploit flaws in its SharePoint service before they were patched, Bloomberg News reported on Friday.