Microsoft (MSFT, Financial) issued an urgent alert regarding active attacks on its SharePoint servers used by enterprises for internal document sharing. These attacks, primarily targeting government and corporate servers, potentially allow attackers to access confidential data or deploy code on private networks. The FBI is investigating and collaborating with federal and private sector partners to address the threat, although detailed information remains undisclosed.
The attacks are classified as "zero-day," exploiting previously unknown security vulnerabilities. However, Microsoft confirmed that its cloud service, SharePoint Online, remains unaffected. Reports indicate that unidentified entities have utilized this vulnerability to launch attacks against both U.S. and international organizations, with tens of thousands of servers at risk.
This vulnerability enables "authorized attackers" to execute deceptive actions through network access, impersonating trusted entities. In response, Microsoft released a security update and urged customers to install it immediately. The company is working closely with the Cybersecurity and Infrastructure Security Agency (CISA) and other global cybersecurity partners to mitigate these threats.
In situations where customers cannot activate malware protection, Microsoft suggested that affected servers should be isolated from the network until updates are applied.