Worldwide cyberattack underway as hackers exploit Microsoft SharePoint zero-day vulnerability

Skye Jacobs

Posts: 1,968   +58
Staff
A hot potato: A newly uncovered security flaw in Microsoft's SharePoint software has sparked a widespread series of cyberattacks targeting government organizations, educational institutions, energy companies, and private enterprises around the globe. This threat has prompted coordinated investigations by authorities in the United States, Canada, and Australia, with cybersecurity experts warning that these intrusions represent one of the most serious server-level breaches seen in recent memory.

"Anybody who's got a hosted SharePoint server has got a problem," Adam Meyers, senior vice president with CrowdStrike, told The Washington Post. "It's a significant vulnerability."

Central to the crisis is a zero-day vulnerability affecting on-premises SharePoint servers, which organizations widely use for managing and sharing internal documents. The Cybersecurity and Infrastructure Security Agency (CISA) reports that attackers have leveraged this flaw, designated CVE-2025-53770, to gain unauthorized remote access to vulnerable systems. While Microsoft's cloud-hosted services such as Microsoft 365 remain unaffected, tens of thousands of traditional SharePoint servers worldwide faced immediate risk.

Microsoft has responded by releasing patches for SharePoint Server 2019 and its Subscription Edition, though users of older versions like SharePoint 2016 continue to await fixes.

Unfortunately, hackers have reportedly obtained cryptographic keys critical for server authentication, allowing them to maintain access even after updates are applied. Consequently, organizations must conduct comprehensive reviews and rotate cryptographic credentials to mitigate ongoing threats.

The revelation of these attacks has sent ripples across public and private sectors. US federal and local government agencies, educational bodies, and European governmental offices are among those scrambling to evaluate system integrity and mitigate damage.

Security researchers from Eye Security, which first detected the exploit, have documented over 50 compromised entities spanning multiple continents.

Disruptions have affected public-facing document repositories in some government offices, forcing agencies to seek alternative means to maintain transparency and access. In industries such as energy and higher education, the implications are particularly severe, as SharePoint servers often connect with other vital services, including Outlook, Teams, and OneDrive, heightening the danger of widespread data theft and password harvesting.

CISA has categorized the exploit as a high-priority threat. The agency advises isolating affected servers from public networks when patches are unavailable and maintaining vigilant monitoring.

Microsoft continues to develop updates targeting legacy products, and cybersecurity organizations like the Center for Internet Security have mobilized to notify vulnerable institutions.

This incident has reignited debates over the reliability of patch management practices and the inherent security risks posed by outdated software systems – a challenge faced by many organizations that rely on legacy technology.

Permalink to story:

 
It reminds me of WEF crisis "predictions". They "predicted" a pandemic, mass migrations, conflicts, global warming and cyber security threats. They could do it sooner than we think. Also they said that in 2030, the US wouldn't be a superpower anymore. Great reset is still rolling.
 
It reminds me of WEF crisis "predictions". They "predicted" a pandemic, mass migrations, conflicts, global warming and cyber security threats. They could do it sooner than we think. Also they said that in 2030, the US wouldn't be a superpower anymore. Great reset is still rolling.
More and more of Trump's decisions just making it more and more look like he is controlled opp... NWO well and truly still on it's way by 2030.
 
This is obviously predetermined obsoleteness- of the systems in place. Microsoft and all of the upper levels of any vulnerable entity have agreed to these things. Why? Since it's not their own data that's on the line. It's the data of their customers, clients and citizens. All this is, is another step forward for the the entire world to submit- "what else can be..."- as one single conglomerate power over everybody else. Everything else is predetermined obsoleteeness in products, services and software- everything!
If you don't see that this is part of a plan, then you need to open your eyes or just go ahead and Bend back over where you were with your head between your knees. there are none in any political or leadership position that makes any decisions on their own values or beliefs. All of them do what they're told when they're told and that's that they are owned and all they're trying to do is continue in their plan to own all of us we'll stay pretty much already do own every facet of Our Lives- and most people have already gladly surrendered their bodily autonomy and ability to make their own decisions in order to be mindless and free of making decisions or having to stand up for themselves in a responsible way. Any free thinkers out there? anybody who wants to exercise free will? Stand together --less than 1% of the population around the world has the mind, will and determination to stand up and everybody else (99.9% of the population) is against us along with the powers that pretend to be.
 
-btw:
Forgot to mention how recently it was discovered that the pentagons systems of software by Microsoft have been available and run through a Chinese communist organization before the monitors that supposedly are watching over them can do anything. These Chinese men or women are highly educated and the people that supposedly monitor them are basically incompetent...
 
Yes, but not in the way you seem to think. This all follows a vision I had forty years ago. And I have great anticipation.



More and more of Trump's decisions just making it more and more look like he is controlled opp... NWO well and truly still on it's way by 2030.


This is obviously predetermined obsoleteness- of the systems in place. Microsoft and all of the upper levels of any vulnerable entity have agreed to these things. Why? Since it's not their own data that's on the line. It's the data of their customers, clients and citizens. All this is, is another step forward for the the entire world to submit- "what else can be..."- as one single conglomerate power over everybody else. Everything else is predetermined obsoleteeness in products, services and software- everything!
If you don't see that this is part of a plan, then you need to open your eyes or just go ahead and Bend back over where you were with your head between your knees. there are none in any political or leadership position that makes any decisions on their own values or beliefs. All of them do what they're told when they're told and that's that they are owned and all they're trying to do is continue in their plan to own all of us we'll stay pretty much already do own every facet of Our Lives- and most people have already gladly surrendered their bodily autonomy and ability to make their own decisions in order to be mindless and free of making decisions or having to stand up for themselves in a responsible way. Any free thinkers out there? anybody who wants to exercise free will? Stand together --less than 1% of the population around the world has the mind, will and determination to stand up and everybody else (99.9% of the population) is against us along with the powers that pretend to be.
 
Back