Hackers Targeting Microsoft SharePoint Servers

5Mind. The Meme Platform

Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted, the U.S. Cyber Security and Infrastructure Defense Agency said.

Hackers are attacking on-premises Microsoft SharePoint server vulnerabilities, the U.S. Cyber Security and Infrastructure Defense Agency (CISA) announced in a July 20 report.

SharePoint Servers are used by organizations to create a private intranet service that builds websites, manages document sharing, and supports other collaborative efforts within the company.

“This exploitation activity, publicly reported as ‘ToolShell,’ provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network,” CISA said, adding that the scope and impact of the new remote code execution (RCE) attack is being assessed.

Microsoft acknowledged the issue a day earlier. In a July 19 guidance report, the company said the exploitation attempt applied to SharePoint servers only. Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted.

The whole SharePoint suite is used by more than 200,000 organizations and 190 million people worldwide, according to the company.

The July security update only partially addresses existing vulnerabilities, Microsoft said. New security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 have been released.

Customers are advised to apply system updates immediately to ensure protection. Security updates for SharePoint 2016 users are not yet released.

Microsoft posted a list of ways that customers can mitigate the attacks. They include installing the latest security updates, using supported versions of on-premises SharePoint Server, making sure the Antimalware Scan Interface is turned on and configured correctly in combination with an antivirus solution, deploying services like Microsoft Defender for Endpoint protection, and rotating SharePoint Server ASP.NET machine keys.

More technical details for advanced hunting techniques and other mitigation efforts are on the Microsoft website.

CISA Recommendations

To reduce risks associated with the RCE exploitation attempt, CISA has several recommendations for organizations. It reiterated Microsoft’s guidance on activating Antimalware Scan Interface (AMSI) and MS Defender on all servers.

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

Jill Biden, The Doctor Of Dishonesty

Dr. Jill Biden, our nation’s former First Lady, is a notorious liar. Throughout her husband’s four-year term as President, she frequently lied about his health.

Facts Are Now Racist? As A Society, We’re Cooked!

If the way you think about another person is based on nothing but the other person’s race, hate to break it to you, but that is racism.

The ballot’s mission creep

Elections are meant to be about ideas, policies, and competence, not personal characteristics that have little bearing on a candidate’s ability to serve.

Tyranny in Virginia

Tyrants are forever in the sights of Progressive politicos....

WATCH: Larry Fink Demands Access to Americans’ Savings, Pension Funds to Bankroll AI

Larry Fink appeared at the “National Skilled Trades Day,” hosted by Texas State Technical College to recruit the electricians he needs to complete the destruction of his AI Death Star.

New Jersey State Police Sets up Protest Zone Outside Immigration Detention Center

Secretary of Homeland Security Markwayne Mullin welcomed the governor’s move to deploy state police to restore order outside the Delaney Hall.

Trump Directs Agencies to Align With Study Recommending Fewer Childhood Vaccines

President Trump signed an executive order directing agencies to align with a scientific assessment that recommended fewer childhood vaccines.

Judge Seeks DOJ Explanation on Bid to Vacate Convictions for Unpardoned Jan. 6 Defendants

A federal judge delayed ruling on the DOJ’s request to vacate convictions tied to the Jan. 6 Capitol breach, citing a need for more information.

Iranian National Used Fake US Company IDs to Steal Military-Grade Technology for Tehran, Treasury Says

Iranian national allegedly used fake U.S. business identities to defrauded dozens of U.S. IT vendors of millions of dollars’ worth of restricted goods.

Trump Suggests Vance’s Anti-Fraud Efforts Could Save Social Security

The president made the comment at a Cabinet meeting...

Trump’s Triumphal Arch Approved by Federal Commission

A commission has approved President Donald Trump’s triumphal arch just outside of Washington, a key step toward making the project a reality.

Trump Details Military Complex Above and Below New White House Ballroom

Trump says planned White House ballroom will be the “safest building ever built,” serving ceremonial and national security purposes.

Senate Confirms 49 Trump Nominees, Including Key Energy Officials

The Senate has confirmed 49 nominees selected by President Trump, including officials tapped to oversee federal land management and energy policy.
spot_img

Related Articles

Popular Categories

MAGA Business Central