Close Menu
Finsider

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    TRX may climb toward $0.50 but PayFi alternatives are stealing market share

    August 3, 2025

    Strategies for Escaping Debt Without Compromising Your Retirement

    August 3, 2025

    WisdomTree Q2 Assets Rise on European Flows and Gains

    August 3, 2025
    Facebook X (Twitter) Instagram
    Trending
    • TRX may climb toward $0.50 but PayFi alternatives are stealing market share
    • Strategies for Escaping Debt Without Compromising Your Retirement
    • WisdomTree Q2 Assets Rise on European Flows and Gains
    • Boost Team Productivity and Security With Windows 11 Pro, Now $15 for Life
    • The ‘120 Minus You Rule’ of Retirement
    • Tim Cook reportedly tells employees Apple ‘must’ win in AI
    • The Rolls-Royce share price smashed its own record this week. Is it too late to buy?
    • DOGE targets $0.80 but newer tokens are attracting long-term whales
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Finsider
    • Markets & Ecomony
    • Tech & Innovation
    • Money & Wealth
    • Business & Startups
    • Visa & Residency
    Finsider
    Home»Business & Startups»Hackers exploiting SharePoint zero-day seen targeting government agencies
    Business & Startups

    Hackers exploiting SharePoint zero-day seen targeting government agencies

    FinsiderBy FinsiderJuly 22, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    microsoft glitch
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The hackers behind the initial wave of attacks exploiting a zero-day in Microsoft SharePoint servers have so far primarily targeted government organizations, according to researchers and news reports.

    Over the weekend, U.S. cybersecurity agency CISA published an alert, warning that hackers were exploiting a previously unknown bug — known as a “zero-day” — in Microsoft’s enterprise data management product SharePoint. While it’s still too early to draw definitive conclusions, it appears that the hackers who first started abusing this flaw were targeting government organizations, according to Silas Cutler, the principal researcher at Censys, a cybersecurity firm that monitors hacking activities on the internet. 

    “It looks like initial exploitation was against a narrow set of targets,” Cutler told TechCrunch. “Likely government related.” 

    “This is a fairly rapidly evolving case. Initial exploitation of this vulnerability was likely fairly limited in terms of targeting, but as more attackers learn to replicate exploitation, we will likely see breaches as a result of this incident,” said Cutler.

    Contact Us

    Do you have more information about these SharePoint attacks? We’d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

    Now that the vulnerability is out there, and is still not fully patched by Microsoft, it’s possible other hackers that are not necessarily working for a government will join in and start abusing it, Cutler said.  

    Cutler added that he and his colleagues are seeing between 9,000 and 10,000 vulnerable SharePoint instances accessible from the internet, but that could change. Eye Security, which first published the existence of the bug, reported seeing a similar number, saying its researchers scanned more than 8,000 SharePoint servers worldwide and found evidence of dozens of compromised servers. 

    Given the limited number of targets and the types of targets at the beginning of the campaign, Cutler explained, it is likely that the hackers were part of a government group, commonly known as an advanced persistent threat.

    Techcrunch event

    San Francisco
    |
    October 27-29, 2025

    The Washington Post reported on Sunday that the attacks targeted U.S. federal and state agencies, as well as universities and energy companies, among other commercial targets. 

    Microsoft said in a blog post that the vulnerability only affects versions of SharePoint that are installed on local networks, and not the cloud versions, which means that each organization that deploys a SharePoint server needs to apply the patch or disconnect it from the internet.

    agencies exploiting Government Hackers SharePoint targeting zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhy Splurging in Retirement is Totally Worth It
    Next Article NewPrinces ‘eyes October listing in London for Princes’
    Finsider
    • Website

    Related Posts

    Business & Startups

    Boost Team Productivity and Security With Windows 11 Pro, Now $15 for Life

    August 3, 2025
    Business & Startups

    Handwave lends a hand to retailers with its European alternative to Amazon’s palm payments

    August 1, 2025
    Business & Startups

    How I Built a Lean, Scalable Business on My Terms

    August 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    TRX may climb toward $0.50 but PayFi alternatives are stealing market share

    August 3, 2025

    Cursor snaps up enterprise startup Koala in challenge to GitHub Copilot

    July 18, 2025

    What is Mistral AI? Everything to know about the OpenAI competitor

    July 18, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Using Gen AI for Early-Stage Market Research

    July 18, 2025

    Cursor snaps up enterprise startup Koala in challenge to GitHub Copilot

    July 18, 2025

    What is Mistral AI? Everything to know about the OpenAI competitor

    July 18, 2025
    news

    TRX may climb toward $0.50 but PayFi alternatives are stealing market share

    August 3, 2025

    Strategies for Escaping Debt Without Compromising Your Retirement

    August 3, 2025

    WisdomTree Q2 Assets Rise on European Flows and Gains

    August 3, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2020 - 2025 The Finsider . Powered by LINC GLOBAL Inc.
    • Contact us
    • Guest Post Policy
    • Privacy Policy
    • Terms of Service

    Type above and press Enter to search. Press Esc to cancel.