Hackers Targeting Microsoft SharePoint Servers

5Mind. The Meme Platform

Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted, the U.S. Cyber Security and Infrastructure Defense Agency said.

Hackers are attacking on-premises Microsoft SharePoint server vulnerabilities, the U.S. Cyber Security and Infrastructure Defense Agency (CISA) announced in a July 20 report.

SharePoint Servers are used by organizations to create a private intranet service that builds websites, manages document sharing, and supports other collaborative efforts within the company.

“This exploitation activity, publicly reported as ‘ToolShell,’ provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network,” CISA said, adding that the scope and impact of the new remote code execution (RCE) attack is being assessed.

Microsoft acknowledged the issue a day earlier. In a July 19 guidance report, the company said the exploitation attempt applied to SharePoint servers only. Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted.

The whole SharePoint suite is used by more than 200,000 organizations and 190 million people worldwide, according to the company.

The July security update only partially addresses existing vulnerabilities, Microsoft said. New security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 have been released.

Customers are advised to apply system updates immediately to ensure protection. Security updates for SharePoint 2016 users are not yet released.

Microsoft posted a list of ways that customers can mitigate the attacks. They include installing the latest security updates, using supported versions of on-premises SharePoint Server, making sure the Antimalware Scan Interface is turned on and configured correctly in combination with an antivirus solution, deploying services like Microsoft Defender for Endpoint protection, and rotating SharePoint Server ASP.NET machine keys.

More technical details for advanced hunting techniques and other mitigation efforts are on the Microsoft website.

CISA Recommendations

To reduce risks associated with the RCE exploitation attempt, CISA has several recommendations for organizations. It reiterated Microsoft’s guidance on activating Antimalware Scan Interface (AMSI) and MS Defender on all servers.

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.

America In Crisis: The Clueless Masses Need To Wake Up!

There seems to be a growing number of Americans who believe this country is some horrible, oppressive nightmare.

Breaching constitutional limits

Bill 1957 would restructure Pennsylvania’s constitution and give abortion and a wide range of “personal reproductive decisions” legal protection.

Chasing the NIL mirage

The Wall Street Journal’s recent dive into Florida’s high school transfer free-for-all should awaken every parent, educator, and legislator.

Corporate Profit Margins Hit All-Time High as Small Doritos Bags Retail at $5.99

Corporate profit margins and raw corporate profits are at record highs, but it’s the margins that really beg questions.

The pro-Hamas crowd: WORSE than antisemites

The pro-Hamas crowd: WORSE than antisemites

Trump Says He Supports Suspending Gas Tax

With gas prices surging 50 percent since the start of the war in Iran, Trump told CBS News on May 11 that stopping excise taxes would be a “great idea.”

Suspect in Attempted Trump Assassination Pleads Not Guilty

Cole Allen, the suspected shooter at the White House Correspondents’ Dinner, pleaded “not guilty” in federal court on May 11.

Republicans Regain Advantage in Redistricting Fight After Virginia Map Overturned

Republicans have regained the advantage in the national mid-decade redistricting battle after the Virginia Supreme Court struck down a map.

Acting CDC Director Says Hantavirus Outbreak ‘Is Not COVID’

CDC’s acting director says the situation is not expected to become a COVID-level outbreak, emphasizing limited widespread risk.

Tech, Business Leaders Set to Accompany Trump on China Trip

President Trump is bringing a delegation of business executives when he travels to China for a summit with Chinese Communist Party leader Xi Jinping.

Trump Nominates FEMA Lead Fired From Role a Year Ago

The WH released a list of nominees for various positions across the federal government, including former Navy SEAL Cameron Hamilton to take over aa lead.

What to Know About Trump’s Presidential Fitness Test Award Revival

In the coming academic year, old-fashioned calisthenics, timed runs, and the spirit of competition could return to many public schools.

Rubio Meets With Pope Leo at the Vatican

Secreetary of State Marco Rubio met with Pope Leo XIV at the Vatican, amid a war of words between the head of the Catholic Church and President Trump.
spot_img

Related Articles

Popular Categories

MAGA Business Central