Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Microsoft warns of active attacks on SharePoint servers

Microsoft has issued a warning about active attacks targeting vulnerabilities in its SharePoint server software.

The flaw is a “zero-day” vulnerability, meaning it was previously unknown and is being exploited before a patch is available.

The FBI has confirmed it is aware of the attacks and is working with federal and private-sector partners.

Experts estimate tens of thousands of servers may be affected.

The attacks impact only on-premises SharePoint servers and do not affect the cloud-based SharePoint Online service.

Microsoft has released a security update for the SharePoint Subscription Edition and is developing updates for the 2016 and 2019 versions.

Organizations unable to apply malware protection are advised to disconnect their servers from the internet until updates are installed.

🔗 Source: Reuters


🧠 Food for thought

1️⃣ Zero-day vulnerabilities continue to pose critical security challenges

This SharePoint attack represents the latest in a concerning pattern of zero-day vulnerabilities being exploited against critical infrastructure.

Zero-day attacks, which target previously unknown vulnerabilities, are particularly dangerous because they exploit security gaps before developers can create patches, giving attackers a significant advantage.

The recommendation to disconnect servers from the internet highlights the severity of this vulnerability, as such drastic measures are typically only suggested when risks are substantial and immediate.

This incident follows several major zero-day exploits in recent years, including the 2020 SolarWinds breach that affected thousands of organizations and multiple federal agencies.

The specific spoofing vulnerability mentioned is particularly concerning as it allows attackers to impersonate trusted entities within organizational networks, potentially enabling them to access sensitive information while appearing legitimate.

2️⃣ The cloud versus on-premises security divide widens

Recent Microsoft developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.