Microsoft fixes 2 SharePoint zero-days under attack
Digest more
Active SharePoint exploits since July 7 target governments and tech firms globally, risking key theft and persistent access.
More details emerged on the ToolShell zero-day attacks targeting SharePoint servers, but confusion remains over the vulnerabilities.
Microsoft issued an emergency fix to close off a vulnerability in its SharePoint software that hackers have exploited to carry out widespread attacks on businesses and at least some federal agencies.
Among the attackers now actively exploiting vulnerable on-premises Microsoft SharePoint servers, at least one has shown indications of originating from China, according to the assessment of researchers at Google Cloud-owned Mandiant.
A major cyberattack has hit Microsoft's SharePoint platforms, putting thousands of organizations at risk around the world. The attack began
Explore more
A sweeping cyber espionage operation targeting Microsoft server software compromised about 100 organizations as of the weekend, two of the organizations that helped uncover the campaign said on Monday.