Microsoft Warns of ‘Zero Day’ Attacks Targeting SharePoint Servers
Microsoft has raised the alarm over active cyberattacks targeting SharePoint server software used by government agencies and businesses to share internal documents. In an alert issued Saturday, the tech giant urged immediate security updates to counter the threat.
The FBI confirmed awareness of the attack campaign and said it is working closely with federal and private-sector partners, although further details remain undisclosed.
Microsoft clarified that the threat only affects on-premise SharePoint servers—cloud-based SharePoint Online in Microsoft 365 remains unaffected.
“We’ve been coordinating closely with CISA, DOD Cyber Defense Command and key cybersecurity partners globally throughout our response,” a Microsoft spokesperson stated.
According to The Washington Post, which first reported the breach, unidentified attackers exploited an undisclosed flaw to launch a sophisticated ‘zero day’ attack—so named because it targets a vulnerability unknown to the software maker. Tens of thousands of servers worldwide may be vulnerable.
In its advisory, Microsoft noted that the exploited vulnerability “allows an authorized attacker to perform spoofing over a network.” Spoofing attacks enable malicious actors to impersonate trusted users or systems, potentially leading to serious breaches in data security and manipulation of systems.
Microsoft recommended applying the latest security patches and advised organizations unable to do so to disconnect vulnerable servers from the internet until updates are available. The company is currently developing patches for SharePoint 2016 and 2019 versions.
The incident underscores ongoing cybersecurity challenges as sophisticated attackers increasingly exploit widely used infrastructure software. Authorities urge organizations to review their systems immediately to mitigate potential damage.
In other news:Raila Odinga Open to Backing Ruto or Kalonzo in 2027 Poll: ‘Can Support Anybody’
Microsoft Warns of ‘Zero Day’ Attacks Targeting SharePoint Servers
