Hackers Targeting Microsoft SharePoint Servers

5Mind. The Meme Platform

Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted, the U.S. Cyber Security and Infrastructure Defense Agency said.

Hackers are attacking on-premises Microsoft SharePoint server vulnerabilities, the U.S. Cyber Security and Infrastructure Defense Agency (CISA) announced in a July 20 report.

SharePoint Servers are used by organizations to create a private intranet service that builds websites, manages document sharing, and supports other collaborative efforts within the company.

“This exploitation activity, publicly reported as ‘ToolShell,’ provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network,” CISA said, adding that the scope and impact of the new remote code execution (RCE) attack is being assessed.

Microsoft acknowledged the issue a day earlier. In a July 19 guidance report, the company said the exploitation attempt applied to SharePoint servers only. Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted.

The whole SharePoint suite is used by more than 200,000 organizations and 190 million people worldwide, according to the company.

The July security update only partially addresses existing vulnerabilities, Microsoft said. New security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 have been released.

Customers are advised to apply system updates immediately to ensure protection. Security updates for SharePoint 2016 users are not yet released.

Microsoft posted a list of ways that customers can mitigate the attacks. They include installing the latest security updates, using supported versions of on-premises SharePoint Server, making sure the Antimalware Scan Interface is turned on and configured correctly in combination with an antivirus solution, deploying services like Microsoft Defender for Endpoint protection, and rotating SharePoint Server ASP.NET machine keys.

More technical details for advanced hunting techniques and other mitigation efforts are on the Microsoft website.

CISA Recommendations

To reduce risks associated with the RCE exploitation attempt, CISA has several recommendations for organizations. It reiterated Microsoft’s guidance on activating Antimalware Scan Interface (AMSI) and MS Defender on all servers.

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

The Poisoning of the Mind: How Public Education Stopped Educating

The most disturbing part of our failing educational system is how few care. Failing to educate children is failing the present and abandoning the future.

“Despite” the Truth

Despite signals media skepticism—like “bless his heart”—subtly masking criticism of Trump’s policies and their real-world impact.

Project Anchor 8/12/2026 Gravity Stops for 7 Seconds

Viral story claims a shadowy “Project Anchor” government operation exists above top secret classification, fueling online speculation and intrigue.

Rubio’s Munich Speech Detailed Trump 2.0’s Envisaged New World Order

Sec. of State & Nat’l Security Adv., Marco Rubio, delivered a historic speech at the Munich Security Conference on Trump 2.0’s world order.

Federalism Isn’t a Relic — It’s America’s Political Shock Absorber

The resistance movement in Minneapolis is a glimpse of future conflict over the expansion of federal power, federalism, and the essential role of states.

FBI Director Kash Patel Says Bureau Uncovered Antifa Funding Sources

FBI Director Kash Patel said on Feb. 18 that the law enforcement agency uncovered what he said are funding sources tied to antifa organizations.

FBI Confirms It Received Thousands of Tips in Nancy Guthrie Case

The FBI received thousands of tips related to the disappearance of “Today” show anchor Savannah Guthrie’s mother as case nears its third week.

Executives Sentenced to 20 Years for $233 Million Obamacare Fraud

The president of an insurance brokerage and a marketing CEO were sentenced to 20 years for a long-running scheme defrauding the ACA program.

Billionaire Wexner Says He Went to Epstein’s Island, Didn’t Know of Crimes

Billionaire Leslie Wexner told lawmakers that he traveled to the island owned by the late sex offender Jeffrey Epstein but did not know of Epstein’s crimes.

Trump Signs Order Declaring Glyphosate Production as Critical to National Security

Trump signed an executive order declaring the U.S. glyphosate supply, a controversial herbicide, critical to national and food security key efforts.

Trump Admin Looks to Release 2.5 Million Acres of Timberland in Oregon

The Trump admin is moving ahead with its plan to possibly release 2.5 million acres of some of the world’s most productive timberland in western Oregon.

Trump to Host Representatives From More Than 40 Countries in First Board of Peace Meeting

President Trump’s Board of Peace meets in Washington with nearly 50 nations and the EU to coordinate efforts to rebuild the Gaza Strip.
spot_img

Related Articles

Popular Categories

MAGA Business Central