Hackers Targeting Microsoft SharePoint Servers

5Mind. The Meme Platform

Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted, the U.S. Cyber Security and Infrastructure Defense Agency said.

Hackers are attacking on-premises Microsoft SharePoint server vulnerabilities, the U.S. Cyber Security and Infrastructure Defense Agency (CISA) announced in a July 20 report.

SharePoint Servers are used by organizations to create a private intranet service that builds websites, manages document sharing, and supports other collaborative efforts within the company.

“This exploitation activity, publicly reported as ‘ToolShell,’ provides unauthenticated access to systems and enables malicious actors to fully access SharePoint content, including file systems and internal configurations, and execute code over the network,” CISA said, adding that the scope and impact of the new remote code execution (RCE) attack is being assessed.

Microsoft acknowledged the issue a day earlier. In a July 19 guidance report, the company said the exploitation attempt applied to SharePoint servers only. Cloud-based SharePoint Online in Microsoft 365 is a different system and is not impacted.

The whole SharePoint suite is used by more than 200,000 organizations and 190 million people worldwide, according to the company.

The July security update only partially addresses existing vulnerabilities, Microsoft said. New security updates that fully protect customers using SharePoint Subscription Edition and SharePoint 2019 have been released.

Customers are advised to apply system updates immediately to ensure protection. Security updates for SharePoint 2016 users are not yet released.

Microsoft posted a list of ways that customers can mitigate the attacks. They include installing the latest security updates, using supported versions of on-premises SharePoint Server, making sure the Antimalware Scan Interface is turned on and configured correctly in combination with an antivirus solution, deploying services like Microsoft Defender for Endpoint protection, and rotating SharePoint Server ASP.NET machine keys.

More technical details for advanced hunting techniques and other mitigation efforts are on the Microsoft website.

CISA Recommendations

To reduce risks associated with the RCE exploitation attempt, CISA has several recommendations for organizations. It reiterated Microsoft’s guidance on activating Antimalware Scan Interface (AMSI) and MS Defender on all servers.

By Naveen Athrappully

Read Full Article on TheEpochTimes.com

Contact Your Elected Officials
The Epoch Times
The Epoch Timeshttps://www.theepochtimes.com/
Tired of biased news? The Epoch Times is truthful, factual news that other media outlets don't report. No spin. No agenda. Just honest journalism like it used to be.
00:02:04

Forged on the frontier

George Washington is widely known as a general and president, but his early life remains obscured by myth, legend, and misunderstanding.
00:02:52

A bobblehead too far

The Orioles did not just hand out a bobblehead. They sent a message that the legacy of their own players is not enough to draw.

Congress fumbles college sports

College sports landscape is a dumpster fire and every sports reporter, broadcaster and fan believes Congress needs to stay out of it.

The Hating Game

The Democrat Party game show should be titled "The Hating Game", played by pitting one class, race, or identity against another for political power.
00:09:50

The Invasion Of The Ballot Snatchers

As election results loom, California faces ballot controversies in a real-life political drama that raises concerns about election integrity.
00:01:55

Judge Refuses to Disqualify Blanche, Pirro From White House Correspondents’ Dinner Shooting Case

A federal judge on June 22 denied Cole Allen’s request to disqualify acting Attorney General Todd Blanche and U.S. Attorney Jeanine Pirro from his case.

Judge Blocks DOJ Subpoenas Aimed at Minnesota Gov. Walz, Other Officials

Federal judge blocks six DOJ subpoenas to Minnesota officials, ruling they unconstitutionally pressured local cooperation with immigration enforcement.

AI Reshaping US Jobs but Not Yet Triggering Mass Unemployment, Says European Central Bank

AI has begun shifting American workers away from occupations most vulnerable to automation, but its overall effect on U.S. employment and wages still remains “muted,”

FBI Urges Caution Before Clicking on Online Ads, Warns of Cybercriminals

The FBI warns that cybercriminals are using online ads to redirect users to fraudulent websites, urging caution before clicking.

Trump Signs Orders to Boost Development in Quantum Computing

President Trump signed two executive orders to accelerate quantum computing development and strengthen U.S. leadership in this emerging technology sector.

Banning Hospitals’ Certain Contracts Could Save Americans $45 Billion, Report Finds

A ban on certain contracts between hospital systems and health insurers could save Americans around $45 billion, according to a report.
00:01:33

Trump Unveils New Air Force One Plane

President Trump unveiled the plane that will serve as the new Air Force One, a Boeing 747-8 luxury jet that was gifted to the US by the Qatari government in 2025.
00:01:27

Trump Threatens 100 Percent Tariff on French Wines Over Digital Services Tax

Trump threatened to impose a 100% tariff on French wines and champagne unless France eliminates its digital services tax on large American tech companies.
spot_img

Related Articles

Popular Categories

MAGA Business Central