The US government, together with Canadian and Australian partners, is investigating a large -scale hacker attack on the SharePoint platform, developed by Microsoft for working together on documents. According to analysts, more than 50 hacks around the world were recorded, including universities, federal agencies in the USA and European state institutions. This is written by The Washington Post.
Under the attack of hackers, in particular, the servers of the energy company in one of the states, servers of at least two federal agencies of the United States, a government institution in Spain, the telecommunication company in Asia (apparently in China) and the University in Brazil.
As the newspaper clarifies, the servers were hacked, which are located precisely inside the organization, and not cloud storage facilities of the Microsoft 365 type. All companies that used SharePoint - a platform designed to exchange and joint work on documents. Microsoft recommended that users make changes to server settings or completely turn them off from the network to prevent leakage. Only in the evening of July 20, the company released security updating for one of the versions of the program, two more remain vulnerable to this day. The first messages about such hacks appeared on Friday, July 18.
Cybersecurity specialists at the same time note that so far they have not observed data removal during the attack on SharePoint. However, hackers gained access to cryptographic keys. These keys can allow them to restore access even after updating the security system, and already compromised servers can still be a danger. According to The Verge, hackers can use this vulnerability to steal confidential data and passwords through services, often connected to Sharepoint: Outlook, Teams and OneDrive.
As the Cybersecurity Agency and Protection of the US infrastructure (CISA) specify , the loophole used by hackers, is a variant of the already existing vulnerability. WP notes that the previous loophole was eliminated.