Anabelle Colaco
23 Jul 2025, 21:29 GMT+10
WASHINGTON, D.C.: Microsoft has warned of active cyberattacks targeting a widely used server software that allows businesses and government agencies to share documents internally. The company urged customers to apply critical security updates immediately to avoid exploitation.
The software under attack is Microsoft's on-premise SharePoint Server, which is commonly deployed by organizations that manage their infrastructure. Microsoft clarified that its cloud-based SharePoint Online service within Microsoft 365 is not affected.
In a security advisory issued on July 19, the company described the threat as a "zero-day" attack, referring to the exploitation of a previously unknown software flaw. According to experts cited by The Washington Post, which first reported the breach, the flaw has been used in recent days to launch cyberattacks against U.S. and international government agencies and businesses. Tens of thousands of servers may be vulnerable.
"We've been coordinating closely with CISA, DOD Cyber Defense Command, and key cybersecurity partners globally throughout our response," a Microsoft spokesperson said. "Security updates have been issued and customers should install them immediately."
The vulnerability allows an attacker with network access to perform "spoofing"—a type of deception in which a malicious actor impersonates a trusted entity. This technique can be used to manipulate systems, financial markets, or internal communications by masking the source of malicious activity.
The FBI confirmed over the weekend that it is aware of the ongoing attacks and is working with federal agencies and private-sector partners to investigate, though it provided no further details.
Microsoft said it is developing updates specifically for the 2016 and 2019 versions of SharePoint. Until those fixes are available, customers unable to implement Microsoft's recommended security configurations should consider disconnecting affected servers from the internet to limit exposure.
Spoofing attacks can be hazardous in environments like government networks or financial institutions, where trust in digital communications is paramount. Microsoft has provided detailed mitigation instructions for system administrators to secure their environments while patches are rolled out.
This incident is the latest in a string of cyber threats affecting critical infrastructure and enterprise tools. These often involve sophisticated attackers exploiting unpatched vulnerabilities before companies are aware they exist.
Get a daily dose of Milwaukee Sun news through our daily email, its complimentary and keeps you fully up to date with world and business news as well.
Publish news of your business, community or sports group, personnel appointments, major event and more by submitting a news release to Milwaukee Sun.
More InformationTOKYO, Japan: In a surprising turn in Japan's upper house elections, the fringe far-right Sanseito party emerged as one of the biggest...
CASTEL GANDOLFO, Italy: Pope Leo has issued a heartfelt appeal for an end to the violence in Gaza, condemning what he described as...
NEW YORK CITY, New York: In recent months, a new and unusual image has become common across the United States: immigration officers...
WASHINGTON, D.C.: U.S. Director of National Intelligence Tulsi Gabbard has caused a significant stir by demanding that former President...
SAN FRANCISCO, California: Microsoft announced July 18 it will no longer allow engineers based in China to provide technical assistance...
WASHINGTON, D.C.: A new controversy has erupted around President Donald Trump's past ties to Jeffrey Epstein, as his administration...
WASHINGTON, D.C.: President Donald Trump announced that Coca-Cola has agreed to begin using real cane sugar in its U.S. beverages following...
(Photo credit: Eric Hartline-Imagn Images) Those working the kitchen at George Webb Restaurants in Wisconsin can turn off the grill....
(Photo credit: Kamil Krzaczynski-Imagn Images) The All-Star break provided a welcome respite for Chicago Cubs rookie third baseman...
(Photo credit: Dan Hamilton-Imagn Images) Cal Raleigh hit his major-league-leading 39th home run of the season and Logan Gilbert...
(Photo credit: Joe Nicholson-Imagn Images) Cal Raleigh hit his major league-leading 39th home run of the season and Logan Gilbert...
(Photo credit: Lucas Peltier-Imagn Images) LAS VEGAS -- At the Big Ten's first-ever media day in Nevada on Tuesday, a portion of...