financetom
Technology
financetom
/
Technology
/
Microsoft server hack likely single actor, thousands of firms now vulnerable, researchers say
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft server hack likely single actor, thousands of firms now vulnerable, researchers say
Jul 21, 2025 6:37 AM

*

Hack exploits previously unknown flaw in SharePoint

software

*

Thousands of entities potentially now vulnerable to attack

*

Hack likely work of one threat actor or group, researcher

says

*

Unclear who is behind attacks

LONDON, July 21 (Reuters) - A global attack on Microsoft ( MSFT )

server software used by thousands of government

agencies and businesses to share documents within organisations

is likely the work of a single actor, a cybersecurity researcher

said on Monday.

Microsoft ( MSFT ) on Saturday issued an alert about "active attacks" on

SharePoint servers used within organisations. It said that

SharePoint Online in Microsoft ( MSFT ) 365, which is in the cloud, was

not hit by the exploit, also known as a "zero day" because it

was previously unknown to cybersecurity researchers.

"Based on the consistency of the tradecraft seen across

observed attacks, the campaign launched on Friday appears to be

a single actor. However, it's possible that this will quickly

change," Rafe Pilling, Director of Threat Intelligence at

Sophos, a British cybersecurity firm.

That tradecraft included the sending of the same digital

payload to multiple targets, Pilling added.

Microsoft ( MSFT ) said it had "provided security updates and

encourages customers to install them," a company spokesperson

said in an emailed statement.

It was not clear who was behind the ongoing hack. The FBI

said on Sunday it was aware of the attacks and was working

closely with its federal and private-sector partners, but

offered no other details. Britain's National Cyber Security

Centre did not immediately respond to a request for comment.

The Washington Post said unidentified actors in the past few

days had exploited a flaw to launch an attack that targeted U.S.

and international agencies and businesses.

According to data from Shodan, a search engine that helps to

identify internet-linked equipment, over 8,000 servers online

could theoretically have already been compromised by hackers.

Those servers include major industrial firms, banks,

auditors, healthcare companies, and several U.S. state-level and

international government entities.

"The SharePoint incident appears to have created a broad

level of compromise across a range of servers globally," said

Daniel Card of British cybersecurity consultancy, PwnDefend.

"Taking an assumed breach approach is wise, and it's also

important to understand that just applying the patch isn't all

that is required here."

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
AT&T beats estimates for subscriber additions on demand for higher-priced plans
AT&T beats estimates for subscriber additions on demand for higher-priced plans
Jul 24, 2024
July 24 (Reuters) - AT&T ( T ) exceeded market expectations for wireless subscriber additions in the second quarter on Wednesday, as the telecom operator's higher-tier unlimited plans attracted customers. The company added 419,000 monthly bill-paying wireless phone subscribers, compared with expectations of 284,800 additions, according to five analysts polled by FactSet. AT&T's ( T ) unlimited plans that are...
EXCLUSIVE: Perfect Corp's Q2 Revenue Jumps 9.6%, YouCam App Subscribers Hit Record High
EXCLUSIVE: Perfect Corp's Q2 Revenue Jumps 9.6%, YouCam App Subscribers Hit Record High
Jul 24, 2024
Perfect Corp ( PERF ) announced financial results for the three months ended June 30, 2024, the second quarter. Total revenue was $13.9 million, compared to $12.7 million year ago, an increase of 9.6%. The increase was primarily due to growth in the revenue of AI- and AR-cloud solutions and mobile app subscriptions. Gross profit was $11.0 million compared with...
Roper Technologies forecasts Q3 profit below estimates on weak enterprise spend
Roper Technologies forecasts Q3 profit below estimates on weak enterprise spend
Jul 24, 2024
July 24 (Reuters) - Software firm Roper Technologies ( ROP ) forecast third-quarter profit below estimates on Wednesday, owing to weak spending and delayed contract renewals by its target industries. An uncertain economy and high borrowing costs are forcing businesses to spend cautiously, delaying contract signing and renewals by clients and impacting firms such as Roper. The company forecast third-quarter...
CrowdStrike says bug in quality control process led to botched update
CrowdStrike says bug in quality control process led to botched update
Jul 24, 2024
LONDON, July 24 (Reuters) - A CrowdStrike ( CRWD ) software update that crashed computers globally last week hitting services from aviation to banking and healthcare was caused by a bug in the U.S. cybersecurity firm's quality control mechanism, the company said on Wednesday. Friday's outage happened because CrowdStrike's ( CRWD ) Falcon Sensor, an advanced platform that protects systems...
Copyright 2023-2025 - www.financetom.com All Rights Reserved