Close Menu
The Politics
    What's Hot

    Belgium urges Europe to drop plan for frozen Russian assets to aid Ukraine

    December 3, 2025

    Inside the Ultra-Orthodox Fight Against Israel’s Draft

    December 3, 2025

    Musk’s Starlink rival Eutelsat shares fall after SoftBank stake cut report

    December 3, 2025
    Facebook X (Twitter) Instagram
    • Demos
    • Politics
    • Buy Now
    Facebook X (Twitter) Instagram
    The Politics
    Subscribe
    Wednesday, December 3
    • Home
    • Breaking
    • World
      • Africa
      • Americas
      • Asia Pacific
      • Europe
    • Sports
    • Politics
    • Business
    • Entertainment
    • Health
    • Tech
    • Weather
    The Politics
    Home»Tech»SharePoint zero-day bug puts government agencies at serious security risk
    Tech

    SharePoint zero-day bug puts government agencies at serious security risk

    Justin M. LarsonBy Justin M. LarsonAugust 3, 2025No Comments6 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Share
    Facebook Twitter Pinterest Email Copy Link


    NEWYou can now listen to Fox News articles!

    Hackers are actively exploiting a new zero-day bug in Microsoft’s SharePoint Server software. The same software is used by key U.S. government agencies, including those tied to national security. 

    The vulnerability affects on-premise versions of SharePoint, allowing attackers to break into systems, steal data and quietly move through connected services. While the cloud version is unaffected, the on-premise version is widely used by major U.S. agencies, universities and private companies. That puts far more than just internal systems at risk.

    Sign up for my FREE CyberGuy Report
    Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER

    NATIONAL SECURITY EXPERTS RAISE CONCERNS AFTER MICROSOFT PROGRAM EXPOSED AS POSSIBLE AVENUE FOR CHINESE SPYING

    microsoft hackers 1

    Microsoft apps on the homescreen of a smartphone   (Kurt “CyberGuy” Knutsson)

    SharePoint zero-day: What you need to know about the exploit

    The exploit was first identified by cybersecurity firm Eye Security July 18. Researchers say it stems from a previously unknown vulnerability chain that can give attackers full control of vulnerable SharePoint servers without needing any credentials. The flaw lets them steal machine keys used to sign authentication tokens, meaning attackers can impersonate legitimate users or services even after a system is patched or rebooted.

    According to Eye Security, the vulnerability appears to be based on two bugs demonstrated at the Pwn2Own security conference earlier this year. While those exploits were initially shared as proof-of-concept research, attackers have now weaponized the technique to target real-world organizations. The exploit chain has been dubbed “ToolShell.”

    WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

    How the SharePoint vulnerability lets hackers access Microsoft services

    Once inside a compromised SharePoint server, hackers can access connected Microsoft services. These include Outlook, Teams and OneDrive. This puts a wide range of corporate data at risk. The attack also allows hackers to maintain long-term access. They can do this by stealing cryptographic material that signs authentication tokens. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to act. It recommends checking systems for signs of compromise and isolating vulnerable servers from the internet.

    Early reports confirmed about 100 victims. Now, researchers believe attackers have compromised more than 400 SharePoint servers worldwide. However, this number refers to servers, not necessarily organizations. According to reports, the number of affected groups is growing rapidly. One of the highest-profile targets is the National Nuclear Security Administration (NNSA). Microsoft confirmed it was targeted but has not confirmed a successful breach.

    Other affected agencies include the Department of Education, Florida’s Department of Revenue and the Rhode Island General Assembly.

    microsoft hackers 2

    Microsoft’s name and logo on a building (Kurt “CyberGuy” Knutsson)

    Microsoft confirms SharePoint exploit and releases patches

    Microsoft confirmed the issue, disclosing that it was aware of “active attacks” exploiting the vulnerability. The company has released patches for SharePoint Server 2016, SharePoint Server 2019 and SharePoint Subscription Edition. Patches for all supported on-prem versions were issued as of July 21.

    GET FOX BUSINESS ON THE GO BY CLICKING HERE

    What you should do about the SharePoint security risk

    If you’re part of a business or organization that runs its own SharePoint servers, especially older on-premise versions, your IT or security team should take this seriously. Even if a system is patched, it could still be at risk if machine keys were stolen. Administrators should also rotate cryptographic keys and audit authentication tokens. For the general public, there’s no action needed right now since this issue doesn’t affect cloud-based Microsoft accounts like Outlook.com, OneDrive or Microsoft 365. But it’s a good reminder to stay cautious online.

    microsoft hackers 3

    Microsoft’s name and logo on a building (Kurt “CyberGuy” Knutsson)

    What you should do about the SharePoint security risk

    If your organization uses on-premise SharePoint servers, take the following steps right away to reduce risk and limit potential damage:

    1. Disconnect vulnerable servers: Take unpatched SharePoint servers offline immediately to prevent active exploitation.

    2. Install available updates: Apply Microsoft’s emergency patches for SharePoint Server 2016, 2019 and Subscription Edition without delay.

    3. Rotate authentication keys: Replace all machine keys used to sign authentication tokens. These may have been stolen and can allow ongoing access even after patching.

    4. Scan for compromise: Check systems for signs of unauthorized access. Look for abnormal login behavior, token misuse or lateral movement within the network.

    5. Enable security logging: Turn on detailed logging and monitoring tools to help detect suspicious activity going forward.

    6. Review connected services: Audit access to Outlook, Teams and OneDrive for signs of suspicious behavior linked to the SharePoint breach.

    7. Subscribe to threat alerts: Sign up for advisories from CISA and Microsoft to stay updated on patches and future exploits.

    8. Consider migration to the cloud: If possible, transition to SharePoint Online, which offers built-in security protection and automatic patching.

    9. Strengthen passwords and use two-factor authentication: Encourage employees to stay vigilant. Even though this exploit targets organizations, it’s a good reminder to enable two-factor authentication (2FA) and use strong passwords. Create strong passwords for all your accounts and devices, and avoid using the same password for multiple online accounts. Consider using a password manager, which securely stores and generates complex passwords, reducing the risk of password reuse. Check out the best expert-reviewed password managers of 2025 at Cyberguy.com/Passwords

    CLICK HERE TO GET THE FOX NEWS APP

    Kurt’s key takeaway

    This SharePoint zero-day shows how fast research can turn into real attacks. What started as a proof-of-concept is now hitting hundreds of real systems, including major government agencies. The scariest part isn’t just the access it gives but how it lets hackers stay hidden even after you patch. 

    Should there be stricter rules around using secure software in government? Let us know by writing to us at Cyberguy.com/Contact

    Sign up for my FREE CyberGuy Report
    Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM/NEWSLETTER

    Copyright 2025 CyberGuy.com.  All rights reserved.  

    Kurt “CyberGuy” Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on “FOX & Friends.” Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.



    Source link

    Related

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
    Justin M. Larson
    • Website

    Related Posts

    Tech

    Phishing emails hide soft hyphens in subject lines to dodge security

    December 2, 2025
    Tech

    Control background app activity on iPhone and Android mobile devices

    December 2, 2025
    Tech

    Apple’s AI chief steps down as company falls behind in tech race | Science, Climate & Tech News

    December 2, 2025
    Tech

    More than 800,000 young children seeing social media content ‘designed to hook adults’, figures show | Science, Climate & Tech News

    December 2, 2025
    Tech

    Scammers exploit Apple Support system to create convincing fake alerts

    December 1, 2025
    Tech

    Airbus fleets return to service after A320 software fixed faster than expected | World News

    December 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    • Africa
    • Americas
    • Asia Pacific
    • Breaking
    • Business
    • Economy
    • Entertainment
    • Europe
    • Health
    • Politics
    • Politics
    • Sports
    • Tech
    • Top Featured
    • Trending Posts
    • Weather
    • World
    Economy News

    Belgium urges Europe to drop plan for frozen Russian assets to aid Ukraine

    Justin M. LarsonDecember 3, 20250

    Nick Beake,Europe correspondentandBruno Boelpaep,Additional reportingAFPBelgian Prime Minister Bart de Wever has written to the European…

    Inside the Ultra-Orthodox Fight Against Israel’s Draft

    December 3, 2025

    Musk’s Starlink rival Eutelsat shares fall after SoftBank stake cut report

    December 3, 2025
    Top Trending

    Belgium urges Europe to drop plan for frozen Russian assets to aid Ukraine

    Justin M. LarsonDecember 3, 20250

    Nick Beake,Europe correspondentandBruno Boelpaep,Additional reportingAFPBelgian Prime Minister Bart de Wever has written…

    Inside the Ultra-Orthodox Fight Against Israel’s Draft

    Justin M. LarsonDecember 3, 20250

    new video loaded: Inside the Ultra-Orthodox Fight Against Israel’s DrafttranscriptBacktranscriptInside the Ultra-Orthodox…

    Musk’s Starlink rival Eutelsat shares fall after SoftBank stake cut report

    Justin M. LarsonDecember 3, 20250

    French satellite group Eutelsat, often seen as Europe’s answer to Elon Musk’s…

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo
    Editors Picks

    Review: Record Shares of Voters Turned Out for 2020 election

    January 11, 2021

    EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

    January 11, 2021

    World’s Most Advanced Oil Rig Commissioned at ONGC Well

    January 11, 2021

    Melbourne: All Refugees Held in Hotel Detention to be Released

    January 11, 2021
    Latest Posts

    Queen Elizabeth the Last! Monarchy Faces Fresh Demand to be Axed

    January 20, 2021

    Review: Russia’s Putin Sets Out Conditions for Peace Talks with Ukraine

    January 20, 2021

    Review: Implications of San Francisco Govts’ Green-Light Nation’s First City-Run Public Bank

    January 20, 2021
    Advertisement
    Demo
    Editors Picks

    Belgium urges Europe to drop plan for frozen Russian assets to aid Ukraine

    December 3, 2025

    Inside the Ultra-Orthodox Fight Against Israel’s Draft

    December 3, 2025

    Musk’s Starlink rival Eutelsat shares fall after SoftBank stake cut report

    December 3, 2025

    US cancels citizenship ceremonies for migrants from travel ban countries

    December 3, 2025
    Latest Posts

    Queen Elizabeth the Last! Monarchy Faces Fresh Demand to be Axed

    January 20, 2021

    Review: Russia’s Putin Sets Out Conditions for Peace Talks with Ukraine

    January 20, 2021

    Review: Implications of San Francisco Govts’ Green-Light Nation’s First City-Run Public Bank

    January 20, 2021
    Advertisement
    Demo
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    News

    • World
    • US Politics
    • EU Politics
    • Business
    • Opinions
    • Connections
    • Science

    Company

    • Information
    • Advertising
    • Classified Ads
    • Contact Info
    • Do Not Sell Data
    • GDPR Policy
    • Media Kits

    Services

    • Subscriptions
    • Customer Support
    • Bulk Packages
    • Newsletters
    • Sponsored News
    • Work With Us

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 The Politics Designed by The Politics.
    • Privacy Policy
    • Terms
    • Accessibility

    Type above and press Enter to search. Press Esc to cancel.