Site navigation

Fresh Wave of Microsoft SharePoint Attacks Leaves Firms Exposed

Tom Quinn

,

Microsoft Sharepoint hack
As more victims emerge, researchers warn the hack may have already given adversaries time to entrench deeper access.

Security researchers have identified around 100 organisations fallen victim to the Microsoft SharePoint hack uncovered just days ago, and which prompted the tech giant to issue an urgent security alert and emergency patches.

Eye Security, the cybersecurity firm that uncovered the hack on Friday (18 July), has been closely monitoring the fallout from the large-scale zero-day exploit, now unfolding in multiple waves, with the latest attack confirmed last night (21 July) by the company’s ‘chief hacker’, Vaisha Bernard.

Working alongside non-profit internet security organisation, The Shadowserver Foundation, the cyber firm said it had scanned over 8,000 public-facing SharePoint environments and identified ‘dozens of separate servers compromised using the exact same payload at the same filepath’.

Since then, others have joined the counter-assault, with Eye Security sharing on social media that another scanning team from the DIVD Dutch Institute for Vulnerability Disclosure identified another twenty victims that had not taken down their SharePoint Server.

As reported by Reuters, The Shadowserver Foundation said that so far most of the impacted organisations have been from the US and Germany, with victims including government organisations.

However, chief hacker Bernard warned that there had been ample time since the initial discovery of the SharePoint vulnerability for malicious actors to spread their reach.

“It’s unambiguous,” Bernard told Reuters, “Who knows what other adversaries have done since to place other backdoors.”

While it remains unclear where the original SharePoint attack originated, security researchers have told the Washington Post, which first revealed the Microsoft hack, that threat actors linked to the Chinese government may be behind the assault.

Speaking anonymously, researchers said investigators had found evidence that the US-based servers compromised through SharePoint systems were communicating with IP addresses located in China, while two other responders working with the US government said they’d spotted signs of early-stage attacks coming out of China as well.


Recommended reading


“We assess that at least one of the actors responsible for this early exploitation is a China-nexus threat actor,” Charles Carmakal, chief technology officer of Google’s Mandiant Consulting, told the Post.

China has some form in this area, having previously been blamed for another large-scale attack in 2021, when Microsoft Exchange servers were targeted, impacting at least 30,000 organisations globally.  

With this latest cyber-attack against Microsoft SharePoint still unfolding, there is potential yet again for tens of thousands of victims, with Adam Meyers, senior vice president with CrowdStrike, telling the Post, “Anybody who’s got a hosted SharePoint server has got a problem.”

Those looking to close these vulnerabilities can find Microsoft’s security updates here.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data