Journos News
Wednesday, October 29, 2025
  • Login
  • Home
  • Breaking News
  • World News
  • Politics
  • Business
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Health
No Result
View All Result
  • Home
  • Breaking News
  • World News
  • Politics
  • Business
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Health
No Result
View All Result
Journos News
No Result
View All Result
Home Technology Cybersecurity & Digital Safety

Microsoft Urges Emergency Fix as Hackers Exploit SharePoint Zero-Day Vulnerability

SharePoint Servers Under Attack: Microsoft Issues Urgent Patch for Zero-Day Flaw

The Daily Desk by The Daily Desk
July 21, 2025
in Cybersecurity & Digital Safety, Cybersecurity & Infrastructure, Tech Industry News, Technology
0
ToolShell Malware Breaches Microsoft SharePoint: Patch Now, Experts Warn - AP Photo/Rick Rycroft, File

Cyberattack Alert: SharePoint Vulnerability Threatens U.S. Agencies and Businesses - AP Photo/Rick Rycroft, File

0
SHARES
3
VIEWS

Microsoft SharePoint Hack: What to Know About the New Zero-Day Vulnerability Affecting Servers Worldwide

A serious security flaw in Microsoft SharePoint is being used by hackers to attack businesses and some U.S. government agencies. Microsoft has issued a warning and is urging anyone using certain versions of SharePoint to patch their systems immediately. The issue affects on-site servers — not cloud-based ones — and could lead to major data breaches if not fixed quickly.

What Is Happening?

Microsoft SharePoint, a platform widely used by companies and organizations for managing files and team collaboration, is currently facing a critical cybersecurity issue. Over the weekend, Microsoft confirmed that hackers are actively exploiting a “zero-day vulnerability” in its SharePoint Server software.

A zero-day vulnerability is a previously unknown flaw in software that hackers can use before a fix is available — meaning developers have had “zero days” to patch it. This makes it especially dangerous.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says the current vulnerability is a variation of an existing issue known as CVE-2025-49706. The exploit allows attackers to gain full access to the SharePoint system, including connected services like Microsoft Teams and OneDrive.

Who Is Affected?

Anyone running Microsoft SharePoint Server software on their own servers — often called “on-premise” servers — is at risk. That includes:

RELATED POSTS

OpenAI Completes For-Profit Conversion, Reshaping Partnership With Microsoft

ELON MUSK UNVEILS GROKIPEDIA AS RIVAL TO WIKIPEDIA

EU Says Meta and TikTok Breached Transparency Rules Under Digital Services Act

  • Government offices
  • Schools and universities
  • Healthcare networks
  • Private businesses of all sizes

It does not affect SharePoint Online, Microsoft’s cloud-based version of the software.

Cybersecurity firm Eye Security said it scanned over 8,000 SharePoint servers around the world and found that dozens had already been compromised. They believe the attacks began on July 18.

What Is the ToolShell Exploit?

Security researchers believe hackers are using a tool known as ToolShell to carry out these attacks. According to Google’s Threat Intelligence Group, this exploit may allow hackers to maintain access even after patches are applied — a big concern for long-term data security.

Adam Meyers, a senior vice president at cybersecurity firm CrowdStrike, said,

“Anybody who’s got a hosted SharePoint server has got a problem. It’s a significant vulnerability.”

The concern is not just about immediate damage. If hackers can maintain access even after companies think they’ve fixed the issue, it could lead to long-lasting breaches and data theft.

What Has Microsoft Done?

Microsoft issued an emergency alert on Saturday, July 20, confirming the vulnerability and saying a fix was on the way. By Sunday, the company had released official guidance on how to patch:

  • SharePoint Server 2019
  • SharePoint Server Subscription Edition

However, Microsoft is still working on a fix for older software — specifically SharePoint Server 2016.

If your organization uses one of these versions, it’s important to apply Microsoft’s patch immediately or follow any temporary workarounds they suggest.

What Should You Do Now?

If your business or agency is running SharePoint Server software on-premise, here’s what experts recommend:

  • Patch immediately. Follow Microsoft’s updated guidance to install the security fix.
  • Take affected servers offline. Both Microsoft and CISA advise disconnecting vulnerable servers from the internet until patches are applied.
  • Check for signs of compromise. Review system logs, audit access, and monitor for unusual activity.
  • Stay updated. Monitor Microsoft’s support page and cybersecurity alerts for the latest developments.

For organizations using SharePoint Online, there’s currently no need to take action — the cloud-based system is not affected by this exploit.

Why This Matters

SharePoint is a core tool for thousands of organizations to manage internal documents and team communications. A security flaw that gives hackers full access to those systems can lead to:

  • Data breaches
  • Ransomware attacks
  • Leaks of confidential files
  • Disruption to internal operations

Because many government agencies and critical services (like healthcare and education) rely on SharePoint, this vulnerability could have wide-reaching effects.

Final Thoughts

This incident is a reminder of the risks involved with running on-premise server software. Unlike cloud-based systems, on-site servers require constant monitoring and manual patching to stay secure.

If your organization hasn’t reviewed its SharePoint setup in a while, now is the time.

The situation is still unfolding, and Microsoft continues to release updates. Make sure your IT teams are staying informed and acting quickly to protect your systems from potential damage.

Source: AP News – What to know about a vulnerability being exploited on Microsoft SharePoint servers

This article was rewritten by JournosNews.com based on verified reporting from trusted sources. The content has been independently reviewed, fact-checked, and edited for accuracy, tone, and global readability in accordance with Google News standards.

Stay informed with JournosNews.com — your trusted source for verified global reporting and in-depth analysis. Follow us on Google News and BlueSky for real-time updates.

JournosNews.com follows Google News content standards with original reporting, verified sources, and global accessibility. Articles are fact-checked and edited for accuracy and neutrality.

Tags: #CISASecurityAdvisory#CloudVsOnPremiseSecurity#CrowdStrikeCyberAlert#CyberAttackWarning#EmergencyServerFix#MicrosoftSecurityUpdate#MicrosoftSharePoint#OnPremiseServerThreat#SharePointPatchAlert#SharePointVulnerability#ToolShellMalware#ZeroDayExploit
ShareSend
The Daily Desk

The Daily Desk

Journos News is a freelance editor and contributor at The Daily Desk, focusing on politics, media, and the shifting dynamics of public discourse. With a decade of experience in digital journalism, Jordan brings clarity and precision to every story.

Related Posts

OpenAI Becomes For-Profit, Reshapes Microsoft Partnership and AI Future - Reuters via BBC

OpenAI Completes For-Profit Conversion, Reshaping Partnership With Microsoft

by The Daily Desk
October 29, 2025
0

OpenAI has officially transitioned into a for-profit company, marking a major turning point in the evolution of one of the...

Elon Musk Launches Grokipedia to Rival Wikipedia, Promising “Truth” and Transparency - AP Photo/Matt Rourke, file

ELON MUSK UNVEILS GROKIPEDIA AS RIVAL TO WIKIPEDIA

by The Daily Desk
October 29, 2025
0

Elon Musk has launched Grokipedia, a new crowdsourced online encyclopedia that he says will rival Wikipedia and serve as a...

EU Says Meta and TikTok Breached Transparency Rules Under Digital Services Act - AP Photo/Kiichiro Sato, File

EU Says Meta and TikTok Breached Transparency Rules Under Digital Services Act

by Journos News
October 24, 2025
0

Meta and TikTok Face EU Scrutiny for Failing Transparency Obligations Under Digital Services Act The European Union has accused Meta...

North Korea Accused of Stealing Billions in Crypto to Fund Nuclear Program - AP Photo/Jon Chol Jin

North Korea Accused of Using Cybercrime to Fund Nuclear and Missile Programs

by Journos News
October 23, 2025
0

North Korea’s cyber operations have become one of its most profitable sources of foreign currency, with hackers allegedly stealing billions...

The Fragile Web: How Sharks, Software Glitches, and Governments Break the Internet - Getty Images

The Fragile Web: How Sharks, Software, and Governments Keep Breaking the Internet

by The Daily Desk
October 20, 2025
0

In a world increasingly dependent on constant connectivity, the internet’s invisible infrastructure has proven alarmingly fragile. The latest widespread outage...

Next Post
Federal Court Hears Harvard’s Lawsuit Against Trump Over Research Funding Freeze - AP Photo/Lisa Poole, File

Harvard Sues Trump Administration Over $2.6 Billion in Federal Funding Cuts

Starbucks Confirms Pumpkin Spice Latte Comeback for 2025: Full Launch Details - AP Photo/Peter Morgan, File

Starbucks Pumpkin Spice Latte Returns August 26: Here’s What to Know for 2025

RECOMMENDED

OpenAI Becomes For-Profit, Reshapes Microsoft Partnership and AI Future - Reuters via BBC

OpenAI Completes For-Profit Conversion, Reshaping Partnership With Microsoft

October 29, 2025
Brigitte Macron’s Daughter Says Cyberbullying Harmed French First Lady’s Health - Getty Images via BBC

Brigitte Macron’s Daughter Says Cyberbullying Damaged First Lady’s Health

October 29, 2025

MOST VIEWED

  • CDs vs. Streaming: Why More Music Lovers Are Switching Back - image credit Headphonesty

    CDs Are Back: Why Audiophiles Are Ditching Streaming

    0 shares
    Share 0 Tweet 0
  • 16 Billion Passwords Leaked: What You Must Do Now to Stay Safe

    0 shares
    Share 0 Tweet 0
  • EU Says Meta and TikTok Breached Transparency Rules Under Digital Services Act

    0 shares
    Share 0 Tweet 0
  • South Korean President Apologizes After Martial Law Controversy

    0 shares
    Share 0 Tweet 0
  • 2025 American Music Awards: Full Winners List and Highlights

    0 shares
    Share 0 Tweet 0

Journos News delivers globally neutral, fact-based journalism that meets international media standards — clear, credible, and made for a connected world.

CATEGORY

SITE LINKS

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

NEWSLETTER

  • About Us
  • Accessibility Statement
  • Contact Us
  • Privacy Policy
  • Terms and Conditions

© JournosNews.com – Trusted source for breaking news, trending stories, and in-depth reports.
All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Breaking News
  • World News
  • Politics
  • Business
  • Conflict and Crisis
  • Sports
  • Technology
  • Entertainment
  • Health

© JournosNews.com – Trusted source for breaking news, trending stories, and in-depth reports.
All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.