Hackers Targeting Microsoft SharePoint Servers

Contact Your Elected Officials

Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted, the U.S. Cyber Security and Infrastructure Defense Agency said.

Hackers are attacking on-premises Microsoft SharePoint server vulnerabilities, the U.S. Cyber Security and Infrastructure Defense Agency (CISA) announced in a July 20 report.

SharePoint Servers are used by organizations to create a private intranet service that builds websites, manages document sharing, and supports other collaborative efforts within the company.

โ€œThis exploitation activity, publicly reported as โ€˜ToolShell,โ€™ provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network,โ€ CISA said, adding that the scope and impact of the new remote code execution (RCE) attack is being assessed.

Microsoft acknowledged the issue a day earlier. In a July 19 guidance report, the company said the exploitation attempt applied to SharePoint servers only. Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted.

The whole SharePoint suite is used by more than 200,000 organizations and 190 million people worldwide, according to the company.

The July security update only partially addresses existing vulnerabilities, Microsoft said. New security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 have been released.

Customers are advised to apply system updates immediately to ensure protection. Security updates for SharePoint 2016 users are not yet released.

Microsoft posted a list of ways that customers can mitigate the attacks. They include installing the latest security updates, using supported versions of on-premises SharePoint Server, making sure the Antimalware Scan Interface is turned on and configured correctly in combination with an antivirus solution, deploying services like Microsoft Defender for Endpoint protection, and rotating SharePoint Server ASP.NET machine keys.

More technical details for advanced hunting techniques and other mitigation efforts are on the Microsoft website.

CISA Recommendations

To reduce risks associated with the RCE exploitation attempt, CISA has several recommendations for organizations. It reiterated Microsoftโ€™s guidance on activating Antimalware Scan Interface (AMSI) and MS Defender on all servers.

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Trump’s Vision for a Safer, Cleaner Washington is Correct

Trump proposed relocating homeless from Washington, D.C.. Benefits include restoring order, protecting the vulnerable, and improving quality of life for all.

IL Gov. Pritzker Homes TX House Dems, Gets Torched!

โ€œTurnabout is fair play.โ€ Trump won and the Republicans took the House and now voting district maps are to be redrawn in the states.

A Cemetery Reminds Us That Reparations Aren’t Simplistic, Race-Based Calculations

One headstone at the Sleepy Hollow cemetery, New York caused me to think about "reparations," which many on the Left are hoping will gain traction.

EBT Recipient to MAHA: โ€˜Youโ€™re Gonna Tell Me I Canโ€™t Have a F***ing Dr. Pepper With My Dinner?โ€™

Dripping with indignation this woman is โ€œdumbfoundedโ€ that she can't purchase Dr. Pepper and brownies with her government-issued EBT card.

A.G. Bill Barr Advised How to Prosecute Trump? Part 2

We last reported on a whistleblower on Project Veritas...

Chikungunya: What It Is, Risk to US, and How to Prevent It

Chikungunya fever is caused by a virus transmitted by infected female mosquitoes which can also transmit dengue and Zika viruses.

Lawmakers Urge State Department to Use Rewards-for-Justice Program to Address CCPโ€™s Forced Organ Harvesting

โ€˜We can ensure that organ procurement is ethical and that no one profits illegally from the organs of Uyghurs, Tibetans, Falun Gong practitioners,โ€™ they wrote.

Fed Official Says Latest Jobs Data Supports 3 Rate Cuts in 2025

One of the Federal Reserve governors said recent job data backs up her position that three interest rate cuts should be instituted in 2025.

Pilot Program Aims to Teach Kids the Value and Potential of Money

Middle School MBA focuses on business economics and is modeled after grad school degree programs scaled to appropriate age group.

Trump Places DC Police Under Federal Control, Orders National Guard to Washington

President Donald Trump announced he will activate hundreds of National Guard troops to be in the nationโ€™s capital to deal with the issue of crime.

Trump Nominates Tammy Bruce as Deputy Representative to UN

President Trump nominated State Dept spokesperson Tammy Bruce as the U.S.โ€™ deputy representative to the U.N. with the rank of ambassador.

US Treasury Sanctions Members of Mexican Cartel โ€˜Los Zetas,โ€™ Including Rapper El Makabelico

Treasury Dept imposed sanctions against high-ranking members and an associate of the Mexican Cartel del Noreste, (Los Zetas) based in Mexico.

Trump Removes IRS Commissioner Billy Long

President Trump is replacing Billy Long as commissioner of the IRS less than two months after his confirmation, a WH official confirmed.
spot_img

Related Articles