Journos News
Monday, December 15, 2025
  • Login
  • Home
  • Breaking News
  • World News
  • Politics
  • Business
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Health
No Result
View All Result
  • Home
  • Breaking News
  • World News
  • Politics
  • Business
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Health
No Result
View All Result
Journos News
No Result
View All Result
Home Technology Cybersecurity & Digital Safety

Microsoft Urges Emergency Fix as Hackers Exploit SharePoint Zero-Day Vulnerability

SharePoint Servers Under Attack: Microsoft Issues Urgent Patch for Zero-Day Flaw

The Daily Desk by The Daily Desk
July 21, 2025
in Cybersecurity & Digital Safety, Cybersecurity & Infrastructure, Tech Industry News, Technology
0
ToolShell Malware Breaches Microsoft SharePoint: Patch Now, Experts Warn - AP Photo/Rick Rycroft, File

Cyberattack Alert: SharePoint Vulnerability Threatens U.S. Agencies and Businesses - AP Photo/Rick Rycroft, File

Microsoft SharePoint Hack: What to Know About the New Zero-Day Vulnerability Affecting Servers Worldwide

A serious security flaw in Microsoft SharePoint is being used by hackers to attack businesses and some U.S. government agencies. Microsoft has issued a warning and is urging anyone using certain versions of SharePoint to patch their systems immediately. The issue affects on-site servers — not cloud-based ones — and could lead to major data breaches if not fixed quickly.

What Is Happening?

Microsoft SharePoint, a platform widely used by companies and organizations for managing files and team collaboration, is currently facing a critical cybersecurity issue. Over the weekend, Microsoft confirmed that hackers are actively exploiting a “zero-day vulnerability” in its SharePoint Server software.

A zero-day vulnerability is a previously unknown flaw in software that hackers can use before a fix is available — meaning developers have had “zero days” to patch it. This makes it especially dangerous.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says the current vulnerability is a variation of an existing issue known as CVE-2025-49706. The exploit allows attackers to gain full access to the SharePoint system, including connected services like Microsoft Teams and OneDrive.

Who Is Affected?

Anyone running Microsoft SharePoint Server software on their own servers — often called “on-premise” servers — is at risk. That includes:

RELATED POSTS

Time Magazine Names “Architects of AI” as 2025 Person of the Year

Australia’s Under-15 Social Media Ban Leaves Rural Teens Worried About Staying Connected

Taiwan Bans Chinese Social Media App Xiaohongshu Amid Fraud and Security Concerns

OpenAI CEO Declares ‘Code Red’ to Boost ChatGPT Amid Growing AI Competition

Australian Teens Challenge Under-16 Social Media Ban, Call for Smarter Online Safety

New Stadium Technology Promises Major Breakthrough for Match-Day Fans

  • Government offices
  • Schools and universities
  • Healthcare networks
  • Private businesses of all sizes

It does not affect SharePoint Online, Microsoft’s cloud-based version of the software.

Cybersecurity firm Eye Security said it scanned over 8,000 SharePoint servers around the world and found that dozens had already been compromised. They believe the attacks began on July 18.

What Is the ToolShell Exploit?

Security researchers believe hackers are using a tool known as ToolShell to carry out these attacks. According to Google’s Threat Intelligence Group, this exploit may allow hackers to maintain access even after patches are applied — a big concern for long-term data security.

Adam Meyers, a senior vice president at cybersecurity firm CrowdStrike, said,

“Anybody who’s got a hosted SharePoint server has got a problem. It’s a significant vulnerability.”

The concern is not just about immediate damage. If hackers can maintain access even after companies think they’ve fixed the issue, it could lead to long-lasting breaches and data theft.

What Has Microsoft Done?

Microsoft issued an emergency alert on Saturday, July 20, confirming the vulnerability and saying a fix was on the way. By Sunday, the company had released official guidance on how to patch:

  • SharePoint Server 2019
  • SharePoint Server Subscription Edition

However, Microsoft is still working on a fix for older software — specifically SharePoint Server 2016.

If your organization uses one of these versions, it’s important to apply Microsoft’s patch immediately or follow any temporary workarounds they suggest.

What Should You Do Now?

If your business or agency is running SharePoint Server software on-premise, here’s what experts recommend:

  • Patch immediately. Follow Microsoft’s updated guidance to install the security fix.
  • Take affected servers offline. Both Microsoft and CISA advise disconnecting vulnerable servers from the internet until patches are applied.
  • Check for signs of compromise. Review system logs, audit access, and monitor for unusual activity.
  • Stay updated. Monitor Microsoft’s support page and cybersecurity alerts for the latest developments.

For organizations using SharePoint Online, there’s currently no need to take action — the cloud-based system is not affected by this exploit.

Why This Matters

SharePoint is a core tool for thousands of organizations to manage internal documents and team communications. A security flaw that gives hackers full access to those systems can lead to:

  • Data breaches
  • Ransomware attacks
  • Leaks of confidential files
  • Disruption to internal operations

Because many government agencies and critical services (like healthcare and education) rely on SharePoint, this vulnerability could have wide-reaching effects.

Final Thoughts

This incident is a reminder of the risks involved with running on-premise server software. Unlike cloud-based systems, on-site servers require constant monitoring and manual patching to stay secure.

If your organization hasn’t reviewed its SharePoint setup in a while, now is the time.

The situation is still unfolding, and Microsoft continues to release updates. Make sure your IT teams are staying informed and acting quickly to protect your systems from potential damage.

Follow JournosNews.com for professionally verified reporting and expert analysis across world events, business, politics, technology, culture, and health — your reliable source for neutral, accurate journalism.
Source: AP News – What to know about a vulnerability being exploited on Microsoft SharePoint servers

This article was rewritten by JournosNews.com based on verified reporting from trusted sources. The content has been independently reviewed, fact-checked, and edited for accuracy, neutrality, tone, and global readability in accordance with Google News and AdSense standards.

All opinions, quotes, or statements from contributors, experts, or sourced organizations do not necessarily reflect the views of JournosNews.com. JournosNews.com maintains full editorial independence from any external funders, sponsors, or organizations.

Stay informed with JournosNews.com — your trusted source for verified global reporting and in-depth analysis. Follow us on Google News, BlueSky, and X for real-time updates.

Tags: #CISASecurityAdvisory#CloudVsOnPremiseSecurity#CrowdStrikeCyberAlert#CyberAttackWarning#EmergencyServerFix#MicrosoftSecurityUpdate#MicrosoftSharePoint#OnPremiseServerThreat#SharePointPatchAlert#SharePointVulnerability#ToolShellMalware#ZeroDayExploit
ShareTweetSend
The Daily Desk

The Daily Desk

The Daily Desk – Contributor, JournosNews.com, The Daily Desk is a freelance editor and contributor at JournosNews.com, covering politics, media, and the evolving dynamics of public discourse. With over a decade of experience in digital journalism, Jordan brings clarity, accuracy, and insight to every story.

Related Posts

Eight leading AI innovators featured on Time’s 2025 cover - AP Photo/Richard Drew
Artificial Intelligence (AI)

Time Magazine Names “Architects of AI” as 2025 Person of the Year

December 12, 2025
Australian teenagers concerned about new national social media restrictions - AP Photo/Rick Rycroft
Australia

Australia’s Under-15 Social Media Ban Leaves Rural Teens Worried About Staying Connected

December 10, 2025
Smartphone showing Xiaohongshu app interface in Taiwan- VCG/AP/CNN
Cybersecurity & Digital Safety

Taiwan Bans Chinese Social Media App Xiaohongshu Amid Fraud and Security Concerns

December 6, 2025
OpenAI CEO Sam Altman announces ChatGPT development priorities - AP Photo/Michael Dwyer, File
Artificial Intelligence (AI)

OpenAI CEO Declares ‘Code Red’ to Boost ChatGPT Amid Growing AI Competition

December 3, 2025
Australian teens challenge new social media ban in national court - Digital Freedom Project/BBC
Australia

Australian Teens Challenge Under-16 Social Media Ban, Call for Smarter Online Safety

November 30, 2025
Fans using mobile devices with enhanced stadium connectivity - Weaver Labs/BBC
Technology

New Stadium Technology Promises Major Breakthrough for Match-Day Fans

November 27, 2025
Llion Jones discusses AI strategy and future innovation in the UK. - Ted AI/BBC
Artificial Intelligence (AI)

AI Pioneer Urges UK to Take Bold Steps in Global Technology Race

November 24, 2025
Russia cellphone internet outages disrupt daily life, prompt public frustration and questions over government restrictions - AP Photo/ Alexander Zemilianichenko
Cybersecurity & Digital Safety

Russia’s Cellphone Internet Outages Spark Public Frustration

November 23, 2025
How to Tell if a Song or Artist is AI-Generated | Journos News - Getty Images/BBC
Artificial Intelligence (AI)

AI-Generated Music: How to Tell if Your Favorite Artist is Real

November 22, 2025
Load More
Next Post
Federal Court Hears Harvard’s Lawsuit Against Trump Over Research Funding Freeze - AP Photo/Lisa Poole, File

Harvard Sues Trump Administration Over $2.6 Billion in Federal Funding Cuts

Starbucks Confirms Pumpkin Spice Latte Comeback for 2025: Full Launch Details - AP Photo/Peter Morgan, File

Starbucks Pumpkin Spice Latte Returns August 26: Here’s What to Know for 2025

Keeping Pets Cool in Record Heat: Vets and Owners Share Essential Tips - AP Photo/Cody Jackson

How to Keep Pets and Horses Safe During Extreme Heatwaves in Florida

JournosNews logo

Journos News delivers globally neutral, fact-based journalism that meets international media standards — clear, credible, and made for a connected world.

  • Categories
  • World News
  • Politics
  • Business & Economy
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Science & Health
  • Lifestyle & Culture
  • Investigations & Watchdog
  • Resources
  • Submit a Story
  • Advertise with Us
  • Syndication & Partnerships
  • Site Map
  • Press & Media Kit
  • Editorial Team
  • Careers
  • AI Use Policy

Join thousands of readers receiving the latest updates, tips, and exclusive insights straight to their inbox. Never miss an important story again.

  • About Us
  • Accessibility Statement
  • Contact Us
  • Privacy Policy
  • Terms and Conditions

© JournosNews.com – Trusted source for breaking news, trending stories, and in-depth reports.
All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Breaking News
  • World News
  • Politics
  • Business
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Health

© JournosNews.com – Trusted source for breaking news, trending stories, and in-depth reports.
All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.