Tag Microsoft

Microsoft Halts Use of China-Based Teams for Department of Defense Support

Microsoft has recently decided to cease using engineering teams based in China for the support of the Defense Department’s cloud computing systems. This decision follows an investigation by ProPublica, which raised concerns among cybersecurity experts about potential vulnerabilities to hacking and espionage. While this action directly addresses the Defense Department,…

Read MoreMicrosoft Halts Use of China-Based Teams for Department of Defense Support

Clorox Sues Service Desk Vendor After $380M Hack for Distributing Passwords Carelessly

Clorox Suffers Major Data Breach Linked to IT Service Provider Negligence In a significant cybersecurity incident, The Clorox Company reported devastating breaches in 2023 that highlight severe vulnerabilities in IT service management. The breach resulted in an estimated financial impact of $380 million, undermining the company’s data integrity and network…

Read MoreClorox Sues Service Desk Vendor After $380M Hack for Distributing Passwords Carelessly

National Nuclear Security Administration Systems Compromised in SharePoint Cyberattack

A recent global cyberattack has targeted critical vulnerabilities in Microsoft’s on-premises SharePoint software, affecting multiple U.S. government agencies, including the National Institutes of Health (NIH) and the National Nuclear Security Administration (NNSA). The breaches were first reported around Friday, July 18, prompting swift action from the impacted organizations and a…

Read MoreNational Nuclear Security Administration Systems Compromised in SharePoint Cyberattack

Essential Information on ToolShell: The SharePoint Vulnerability Facing Widespread Exploitation

Microsoft has recently addressed two critical vulnerabilities, CVE-2025-49706 and CVE-2025-49704, part of their monthly update cycle. However, reports from over the weekend have revealed that the patches were insufficient, leaving organizations vulnerable to new types of cyberattacks. The primary targets of these attacks are organizations using SharePoint servers. The initial…

Read MoreEssential Information on ToolShell: The SharePoint Vulnerability Facing Widespread Exploitation

Microsoft Places Older SharePoint Versions on Life Support, Leaving Them Vulnerable to Hackers

Numerous organizations globally experienced data breaches this week, following the exploitation of a recently discovered vulnerability in older versions of Microsoft’s SharePoint file-sharing platform. This wave of attacks further complicates the cybersecurity landscape for institutions that have relied on SharePoint, as they face heightened risk while Microsoft shifts its focus…

Read MoreMicrosoft Places Older SharePoint Versions on Life Support, Leaving Them Vulnerable to Hackers

Microsoft Links On-Premises SharePoint Exploits to China

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime, Governance & Risk Management Security Researchers Warn of Widespread Access to Exploit Code by Diverse Hacking Groups Mathew J. Schwartz (euroinfosec) • July 22, 2025 Image: Shutterstock/Microsoft Recent assessments indicate that hackers have been exploiting zero-day vulnerabilities in Microsoft SharePoint, primarily to…

Read MoreMicrosoft Links On-Premises SharePoint Exploits to China

Global Exploitation of SharePoint Vulnerability with a Severity Rating of 9.8

The ongoing issues following recent software updates highlight a critical aspect of cybersecurity: infections can enable attackers to steal authentication credentials, granting extensive access to sensitive resources within a compromised network. While installing necessary updates is an initial step in recovery, further actions are imperative for complete remediation. On July…

Read MoreGlobal Exploitation of SharePoint Vulnerability with a Severity Rating of 9.8

Attackers Take Advantage of Zero-Day Vulnerabilities in On-Premises SharePoint

Governance & Risk Management, Patch Management Microsoft Rolls Out Emergency Patches for Authentication-Bypassing Attacks Prajeet Nair (@prajeetspeaks), Mathew J. Schwartz (euroinfosec) • July 21, 2025 Image: Shutterstock In a concerning development, cybersecurity experts have reported that attackers are exploiting two zero-day vulnerabilities in on-premises Microsoft SharePoint installations. This activity allows…

Read MoreAttackers Take Advantage of Zero-Day Vulnerabilities in On-Premises SharePoint