No Result
View All Result
Sunday, September 14, 2025
  • Login
NEWSLETTER
JOURNOS NEWS
26 °c
Columbus
23 ° Sun
23 ° Mon
  • Home
  • World News
  • Business
  • Politics
  • Sports
  • Entertainment
  • Technology
  • Lifestyle
  • Science
  • Health
  • Home
  • World News
  • Business
  • Politics
  • Sports
  • Entertainment
  • Technology
  • Lifestyle
  • Science
  • Health
26 °c
Columbus
23 ° Sun
23 ° Mon
No Result
View All Result
JOURNOS NEWS
No Result
View All Result
Home Technology Cybersecurity & Digital Safety

Microsoft Urges Emergency Fix as Hackers Exploit SharePoint Zero-Day Vulnerability

SharePoint Servers Under Attack: Microsoft Issues Urgent Patch for Zero-Day Flaw

by The Daily Desk
July 21, 2025
in Cybersecurity & Digital Safety, Cybersecurity & Infrastructure, Tech Industry News, Technology
0
ToolShell Malware Breaches Microsoft SharePoint: Patch Now, Experts Warn - AP Photo/Rick Rycroft, File

Cyberattack Alert: SharePoint Vulnerability Threatens U.S. Agencies and Businesses - AP Photo/Rick Rycroft, File

Microsoft SharePoint Hack: What to Know About the New Zero-Day Vulnerability Affecting Servers Worldwide

A serious security flaw in Microsoft SharePoint is being used by hackers to attack businesses and some U.S. government agencies. Microsoft has issued a warning and is urging anyone using certain versions of SharePoint to patch their systems immediately. The issue affects on-site servers — not cloud-based ones — and could lead to major data breaches if not fixed quickly.

What Is Happening?

Microsoft SharePoint, a platform widely used by companies and organizations for managing files and team collaboration, is currently facing a critical cybersecurity issue. Over the weekend, Microsoft confirmed that hackers are actively exploiting a “zero-day vulnerability” in its SharePoint Server software.

A zero-day vulnerability is a previously unknown flaw in software that hackers can use before a fix is available — meaning developers have had “zero days” to patch it. This makes it especially dangerous.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says the current vulnerability is a variation of an existing issue known as CVE-2025-49706. The exploit allows attackers to gain full access to the SharePoint system, including connected services like Microsoft Teams and OneDrive.

Who Is Affected?

Anyone running Microsoft SharePoint Server software on their own servers — often called “on-premise” servers — is at risk. That includes:

  • Government offices
  • Schools and universities
  • Healthcare networks
  • Private businesses of all sizes

It does not affect SharePoint Online, Microsoft’s cloud-based version of the software.

Cybersecurity firm Eye Security said it scanned over 8,000 SharePoint servers around the world and found that dozens had already been compromised. They believe the attacks began on July 18.

What Is the ToolShell Exploit?

Security researchers believe hackers are using a tool known as ToolShell to carry out these attacks. According to Google’s Threat Intelligence Group, this exploit may allow hackers to maintain access even after patches are applied — a big concern for long-term data security.

Adam Meyers, a senior vice president at cybersecurity firm CrowdStrike, said,

More RelatedPosts

Google Unveils Pixel 10 Series, Pixel Watch 4, and Pixel Buds 2a at Hardware Event

UK Withdraws Controversial Apple Data Access Demand

How Language Shapes the Hidden Internet You Don’t See

Louisiana Sues Roblox Over Alleged Failure to Protect Children Online

Load More

“Anybody who’s got a hosted SharePoint server has got a problem. It’s a significant vulnerability.”

The concern is not just about immediate damage. If hackers can maintain access even after companies think they’ve fixed the issue, it could lead to long-lasting breaches and data theft.

What Has Microsoft Done?

Microsoft issued an emergency alert on Saturday, July 20, confirming the vulnerability and saying a fix was on the way. By Sunday, the company had released official guidance on how to patch:

  • SharePoint Server 2019
  • SharePoint Server Subscription Edition

However, Microsoft is still working on a fix for older software — specifically SharePoint Server 2016.

If your organization uses one of these versions, it’s important to apply Microsoft’s patch immediately or follow any temporary workarounds they suggest.

What Should You Do Now?

If your business or agency is running SharePoint Server software on-premise, here’s what experts recommend:

  • Patch immediately. Follow Microsoft’s updated guidance to install the security fix.
  • Take affected servers offline. Both Microsoft and CISA advise disconnecting vulnerable servers from the internet until patches are applied.
  • Check for signs of compromise. Review system logs, audit access, and monitor for unusual activity.
  • Stay updated. Monitor Microsoft’s support page and cybersecurity alerts for the latest developments.

For organizations using SharePoint Online, there’s currently no need to take action — the cloud-based system is not affected by this exploit.

Why This Matters

SharePoint is a core tool for thousands of organizations to manage internal documents and team communications. A security flaw that gives hackers full access to those systems can lead to:

  • Data breaches
  • Ransomware attacks
  • Leaks of confidential files
  • Disruption to internal operations

Because many government agencies and critical services (like healthcare and education) rely on SharePoint, this vulnerability could have wide-reaching effects.

Final Thoughts

This incident is a reminder of the risks involved with running on-premise server software. Unlike cloud-based systems, on-site servers require constant monitoring and manual patching to stay secure.

If your organization hasn’t reviewed its SharePoint setup in a while, now is the time.

The situation is still unfolding, and Microsoft continues to release updates. Make sure your IT teams are staying informed and acting quickly to protect your systems from potential damage.

Source: AP News – What to know about a vulnerability being exploited on Microsoft SharePoint servers

The Daily Desk

The Daily Desk

J News is a freelance editor and contributor at The Daily Desk, focusing on politics, media, and the shifting dynamics of public discourse. With a decade of experience in digital journalism, Jordan brings clarity and precision to every story.

Related Posts

At its 2025 hardware event, Google reveals Pixel 10 lineup, Pixel Watch 4, and Pixel Buds 2a, highlighting AI innovation and repairable designs. - Julian Chokkattu/WIRED
Gadgets & Devices

Google Unveils Pixel 10 Series, Pixel Watch 4, and Pixel Buds 2a at Hardware Event

August 20, 2025
UK Government Withdraws Request for Apple “Back Door,” Preserving Privacy for Users and Avoiding Potential U.S. Civil Liberties Issues - Getty Images/BBC
Data Privacy & Security

UK Withdraws Controversial Apple Data Access Demand

August 19, 2025
The Real Internet You Don’t See: Language Barriers Create Distinct Digital Cultures Across YouTube, Social Media, and Online Content - Serenity Strull/ Getty Images/BBC
EDITORS PICK

How Language Shapes the Hidden Internet You Don’t See

August 15, 2025
Roblox Faces Lawsuit in Louisiana Over Child Safety Concerns as Attorney General Cites Predatory Activity - AP Photo/Leon Keith, File
Cybersecurity & Digital Safety

Louisiana Sues Roblox Over Alleged Failure to Protect Children Online

August 15, 2025
GPT-5 Launch Triggers Global Criticism as Users Report Errors, Dull Responses, and Feature Loss - Nathan Laine/Bloomberg/Getty Images
AI Ethics & Accountability

OpenAI Faces Backlash Over GPT-5 Rollout as Users Report Errors and Personality Shift

August 14, 2025
April dam incident in Norway linked to pro-Russian hackers, raising concerns over cybersecurity for water management and other critical systems. - Fredrik Varfjell/NTB Scanpix via AP, file
Cybersecurity & Digital Safety

Norway Suspects Pro-Russian Hackers Behind Dam Sabotage Incident

August 14, 2025
New YouTube AI system tests viewer age verification in U.S., enhancing protections for minors and restricting - AP Photo/Juliana Yamadainappropriate content based on watching habits.
Artificial Intelligence (AI)

YouTube Launches AI-Powered Age Verification Test to Protect Young Viewers

August 12, 2025
Musk Alleges Apple Antitrust Violation After X and Grok AI Are Left Out of App Store’s ‘Must Have’ List Despite Strong Download Numbers - AP Photo/Rick Rycroft, File
Artificial Intelligence (AI)

Elon Musk Threatens Legal Action Against Apple Over App Store Rankings

August 12, 2025
After Decades of Service, AOL Announces Shutdown of Dial-Up Internet on September 30, Reflecting Growing Broadband Adoption Trends - Thomas Fuller/SOPA Images/Shutterstock
Internet & Connectivity

AOL Ends Dial-Up Internet Service After Over 30 Years

August 11, 2025
Load More
Next Post
Federal Court Hears Harvard’s Lawsuit Against Trump Over Research Funding Freeze - AP Photo/Lisa Poole, File

Harvard Sues Trump Administration Over $2.6 Billion in Federal Funding Cuts

Starbucks Confirms Pumpkin Spice Latte Comeback for 2025: Full Launch Details - AP Photo/Peter Morgan, File

Starbucks Pumpkin Spice Latte Returns August 26: Here’s What to Know for 2025

Keeping Pets Cool in Record Heat: Vets and Owners Share Essential Tips - AP Photo/Cody Jackson

How to Keep Pets and Horses Safe During Extreme Heatwaves in Florida

Gaza Humanitarian Crisis Sparks Unified Call for Ceasefire from 25 Countries - AP Photo/Jehad Alshrafi

25 Countries Demand Gaza Ceasefire, Urge Israel to Follow International Law

China’s Brain Tech Advances Signal New Rivalry with U.S. in Neural Implants - CNN

China Challenges Neuralink with Breakthrough in Brain-Computer Interface Technology

Popular News

  • Kathmandu Streets Reopen as Nepal Ends Curfew Following Violent Protests Over Social Media Ban and Appointment of First Woman Prime Minister - (AP Photo/Niranjan Shrestha

    Nepal Lifts Curfew After Deadly Protests as First Woman Prime Minister Takes Office

    0 shares
    Share 0 Tweet 0
  • Young Utah Man Arrested in Charlie Kirk Shooting Had No Prior Criminal Record

    0 shares
    Share 0 Tweet 0
  • Gramatica’s Last-Second Field Goal Lifts South Florida Over No. 13 Florida in Gainesville Stunner

    0 shares
    Share 0 Tweet 0
  • Israel Orders Gaza City Evacuations and Strikes High-Rise Towers as Humanitarian Crisis Deepens

    0 shares
    Share 0 Tweet 0
  • Trump Administration Considers Federal Role in New York’s 9/11 Memorial

    0 shares
    Share 0 Tweet 0

Recommended

New York City Feels the Sting of Fewer Overseas Tourists - Yuki Iwamura/Bloomberg/Getty Images

Why Fewer Foreign Tourists Are Visiting New York City

3 months ago
How The Beatles Brought Joy to a Mourning America After JFK’s Death

How The Beatles Brought Joy to a Mourning America After JFK’s Death

10 months ago

Connect with us

  • About Us
  • Contact Us
  • Cookie Settings
  • Privacy Policy
  • Terms and Conditions
  • Support Press Freedom
  • Accessibility Statement
  • Advertising
  • Online Shopping
Breaking News That Keeps You Ahead.

Copyright © 2024 JournosNews.com All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • World News
  • Business
  • Politics
  • Sports
  • Entertainment
  • Technology
  • Lifestyle
  • Science
  • Health

Copyright © 2024 JournosNews.com All rights reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.