HomeScience & EnvironmentSharePoint zero-day bug puts...

SharePoint zero-day bug puts government agencies at serious security risk

NEWYou can now listen to Fox News articles!

Hackers are actively exploiting a new zero-day bug in Microsoft’s SharePoint Server software. The same software is used by key U.S. government agencies, including those tied to national security. 

The vulnerability affects on-premise versions of SharePoint, allowing attackers to break into systems, steal data and quietly move through connected services. While the cloud version is unaffected, the on-premise version is widely used by major U.S. agencies, universities and private companies. That puts far more than just internal systems at risk.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER

NATIONAL SECURITY EXPERTS RAISE CONCERNS AFTER MICROSOFT PROGRAM EXPOSED AS POSSIBLE AVENUE FOR CHINESE SPYING

Microsoft apps on the homescreen of a smartphone   (Kurt “CyberGuy” Knutsson)

SharePoint zero-day: What you need to know about the exploit

The exploit was first identified by cybersecurity firm Eye Security July 18. Researchers say it stems from a previously unknown vulnerability chain that can give attackers full control of vulnerable SharePoint servers without needing any credentials. The flaw lets them steal machine keys used to sign authentication tokens, meaning attackers can impersonate legitimate users or services even after a system is patched or rebooted.

According to Eye Security, the vulnerability appears to be based on two bugs demonstrated at the Pwn2Own security conference earlier this year. While those exploits were initially shared as proof-of-concept research, attackers have now weaponized the technique to target real-world organizations. The exploit chain has been dubbed “ToolShell.”

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

How the SharePoint vulnerability lets hackers access Microsoft services

Once inside a compromised SharePoint server, hackers can access connected Microsoft services. These include Outlook, Teams and OneDrive. This puts a wide range of corporate data at risk. The attack also allows hackers to maintain long-term access. They can do this by stealing cryptographic material that signs authentication tokens. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to act. It recommends checking systems for signs of compromise and isolating vulnerable servers from the internet.

Early reports confirmed about 100 victims. Now, researchers believe attackers have compromised more than 400 SharePoint servers worldwide. However, this number refers to servers, not necessarily organizations. According to reports, the number of affected groups is growing rapidly. One of the highest-profile targets is the National Nuclear Security Administration (NNSA). Microsoft confirmed it was targeted but has not confirmed a successful breach.

Other affected agencies include the Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly.

microsoft hackers 2

Microsoft’s name and logo on a building (Kurt “CyberGuy” Knutsson)

Microsoft confirms SharePoint exploit and releases patches

Microsoft confirmed the issue, disclosing that it was aware of “active attacks” exploiting the vulnerability. The company has released patches for SharePoint Server 2016, SharePoint Server 2019 and SharePoint Subscription Edition. Patches for all supported on-prem versions were issued as of July 21.

GET FOX BUSINESS ON THE GO BY CLICKING HERE

What you should do about the SharePoint security risk

If you’re part of a business or organization that runs its own SharePoint servers, especially older on-premise versions, your IT or security team should take this seriously. Even if a system is patched, it could still be at risk if machine keys were stolen. Administrators should also rotate cryptographic keys and audit authentication tokens. For the general public, there’s no action needed right now since this issue doesn’t affect cloud-based Microsoft accounts like Outlook.com, OneDrive or Microsoft 365. But it’s a good reminder to stay cautious online.

microsoft hackers 3

Microsoft’s name and logo on a building (Kurt “CyberGuy” Knutsson)

What you should do about the SharePoint security risk

If your organization uses on-premise SharePoint servers, take the following steps right away to reduce risk and limit potential damage:

1. Disconnect vulnerable servers: Take unpatched SharePoint servers offline immediately to prevent active exploitation.

2. Install available updates: Apply Microsoft’s emergency patches for SharePoint Server 2016, 2019 and Subscription Edition without delay.

3. Rotate authentication keys: Replace all machine keys used to sign authentication tokens. These may have been stolen and can allow ongoing access even after patching.

4. Scan for compromise: Check systems for signs of unauthorized access. Look for abnormal login behavior, token misuse or lateral movement within the network.

5. Enable security logging: Turn on detailed logging and monitoring tools to help detect suspicious activity going forward.

6. Review connected services: Audit access to Outlook, Teams and OneDrive for signs of suspicious behavior linked to the SharePoint breach.

7. Subscribe to threat alerts: Sign up for advisories from CISA and Microsoft to stay updated on patches and future exploits.

8. Consider migration to the cloud: If possible, transition to SharePoint Online, which offers built-in security protection and automatic patching.

9. Strengthen passwords and use two-factor authentication: Encourage employees to stay vigilant. Even though this exploit targets organizations, it’s a good reminder to enable two-factor authentication (2FA) and use strong passwords. Create strong passwords for all your accounts and devices, and avoid using the same password for multiple online accounts. Consider using a password manager, which securely stores and generates complex passwords, reducing the risk of password reuse. Check out the best expert-reviewed password managers of 2025 at Cyberguy.com/Passwords

CLICK HERE TO GET THE FOX NEWS APP

Kurt’s key takeaway

This SharePoint zero-day shows how fast research can turn into real attacks. What started as a proof-of-concept is now hitting hundreds of real systems, including major government agencies. The scariest part isn’t just the access it gives but how it lets hackers stay hidden even after you patch. 

Should there be stricter rules around using secure software in government? Let us know by writing to us at Cyberguy.com/Contact

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER

Copyright 2025 CyberGuy.com.  All rights reserved.  

Source link

- A word from our sponsors -

spot_img

Most Popular

More from Author

- A word from our sponsors -

spot_img

Read Now

Chris Hemsworth’s Thor sets the tone serious for ‘Avengers: Doomsday’

Chris Hemsworth is signaling a major tonal shift for Thor as Marvel Studios prepares audiences for Avengers: Doomsday, and...

PPF, Post Office FD, SSY: Govt Keeps Interest Rates On Small Savings Schemes Unchanged For Q4 FY26 | Savings and Investments News

Last Updated:December 31, 2025, 20:02 ISTPPF, NSC, SSY, KVP, Post Office Deposits: Check latest interest rates on small savings schemes for the period between January 1 to March 31 this year.Small savings schemes rate update.PPF, Post Office FD, SSY, NSC Interest Rates: The government on Wednesday, December...

Rupee outlook 2026: Why the rupee may stay under stress next year; here’s what experts say

The Indian rupee is set to face sharp and persistent volatility through 2026 as capital outflows, tariff-related trade disruptions and weak foreign investment flows continue to outweigh the country’s strong macroeconomic fundamentals, analysts and official data indicate, PTI reported.Despite steady growth and moderate inflation at...

Why This Glacier Worries Scientists the Most

new video loaded: Why This Glacier Worries Scientists the MostOur climate reporter Raymond Zhong describes how the fast-melting Thwaites Glacier of Antarctica, is like a cork in a bottle: If it starts to really disintegrate, many more glaciers around it could do the same, with major consequences...

Stock Market Holidays 2026: Are NSE, BSE Open Or Closed On December 31, January 01? | Markets News

Last Updated:December 30, 2025, 16:01 ISTWill NSE and BSE remain open on December 31 and January 1 in 2026? Check NSE, BSE holidays list for 2026?NSE Holiday 2026: Will stock market be closed on New Year? NSE Holidays 2026: As the calendar flips and investors step into...

What is happening to gas and electricity prices?

Getty ImagesTypical household energy costs will increase slightly on Thursday when the new energy price cap takes effect. Separately, the regulator Ofgem has said customer bills will rise by around £30 a year over the next six years to help fund a major investment in the UK's...

Who Is Ruby Franke? The rise and fall of the family vlogger convicted of child abuse

Your support helps us to tell the storyFrom reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines...

Blue Origin astronaut reveals depression after space flight backlash

A Vietnamese-American astronaut has opened up about her depression after she received a "tsunami of harassment" following the first all-female space trip since 1963 earlier this year.Amanda Nguyen - a 34-year-old scientist and civil rights activist - was part of the 11-minute Blue Origin space flight, which...

Beyoncé is now a billionaire, according to Forbes

Beyoncé once said, "It should cost a billion to look this good," and now she can afford it. The Grammy-winning artist is now a billionaire, becoming the fifth...

India’s FDI squeeze – India Today

One of the narratives of the Bharatiya Janata Party on the eve of the general election in May-June this year was that India, under the Narendra Modi government, was beginning to claim her rightful place in the world. It was growing at 7 per cent, was...

GM’s record stock performance beats Tesla, Ford in 2025

Mary Barra, CEO of General Motors, attends the annual Allen and Co. Sun Valley Media and Technology Conference at the Sun Valley Resort in Sun Valley, Idaho, on July 8, 2025.David A. Grogan | CNBCDETROIT — General Motors is on pace to be the top U.S.-traded automaker...

The biggest health myths we finally stopped believing in 2025 |

Sometimes long held beliefs are tested when science weighs in. Whether these are theories or claims, emerging studies and research are consistently separating the facts from myths. When it came to health myths this year, scientific evidence has put a stop to some of them....