Connect with us

Hi, what are you looking for?

Technology

SharePoint Security Flaw Exposes Thousands, Breaches US Nuclear Agency

A significant security breach affecting Microsoft’s SharePoint platform has put over 10,000 organizations worldwide at risk. This vulnerability, which allows hackers to exploit on-premises servers, has primarily impacted companies in the United States, but also extends to regions including the Netherlands, United Kingdom, and Canada. Among the organizations compromised is the National Nuclear Security Administration (NNSA), which oversees the country’s nuclear arsenal.

Microsoft reported that there are “active attacks targeting on-premises servers.” The breach has raised alarms among cybersecurity experts, who describe the vulnerability as a “dream” for hackers, particularly for those deploying ransomware. Notably, Silas Cutler, a researcher at Michigan-based cybersecurity firm Censys, highlighted the extensive reach of the breach, warning that many organizations could face serious consequences.

Extent of the Vulnerability

The security flaw was first identified by Eye Security, which cautioned that the vulnerability allows hackers to gain unauthorized access to SharePoint servers. This access could enable them to steal keys that permit impersonation of users or services, even if the server is later patched. Eye Security further noted that hackers might retain access through backdoors or modified components that can endure system updates and reboots.

In light of these developments, Microsoft has issued a security patch for the SharePoint Subscription Edition and is actively working on similar updates for SharePoint 2016 and 2019. Despite these measures, cybersecurity firms stress that the risks remain significant. Reports from both Palo Alto Networks and Google’s Threat Intelligence Group have characterized the risks as “serious.”

Response from Affected Organizations

Organizations that utilize SharePoint are urged to take immediate precautions. Microsoft has provided guidelines for recommended actions, but experts suggest that organizations may want to consider temporarily removing sensitive documents from SharePoint until the situation stabilizes. Given the magnitude of the threat, many companies are likely to reassess their data storage strategies and cybersecurity measures in light of this breach.

While no sensitive or classified information is believed to have been compromised in the incident involving the NNSA, the breach underscores vulnerabilities within critical infrastructures. The NNSA, responsible for maintaining the nation’s nuclear weapons, is now part of a growing list of entities facing heightened cybersecurity threats.

As cybersecurity measures evolve, organizations must remain vigilant. The ongoing situation serves as a reminder of the importance of robust security protocols in safeguarding sensitive information from increasingly sophisticated cyber threats.

You May Also Like

Lifestyle

Shares of **Amerant Bancorp** (NYSE:AMTB) received an upgrade from Wall Street Zen on March 10, 2024, transitioning from a hold rating to a buy...

Top Stories

UPDATE: Sydney Sweeney’s Baskin-Robbins advertisement is making waves online as backlash intensifies over her recent American Eagle campaign. Just days after critics condemned the...

Sports

The UFC event in Abu Dhabi on July 26, 2025, featured a record-breaking performance from Steven Nguyen, who achieved an unprecedented feat by knocking...

Top Stories

BREAKING: The historic Durango-La Plata Aquatic Center, a cornerstone of community recreation since its opening in August 1958, is facing imminent demolition as part...

Business

An off-Strip casino in Las Vegas has unveiled Nevada’s latest sportsbook, Boomer’s Sports Book, as part of a substantial renovation. The new facility opened...

Health

The ongoing impact of poverty on children’s health has prompted urgent calls for action from mental health advocacy groups. With a notable rise in...

Top Stories

URGENT UPDATE: Affordable motorcycle helmets under ₹1000 are now available for safety-conscious riders across India. With road safety becoming a pressing issue, these helmets...

Sports

The Las Vegas Aces secured a convincing victory over the Los Angeles Sparks, defeating them 89-74 on March 12, 2024, at Crypto.com Arena. This...

Technology

Polish cyclist Michał Kwiatkowski returned to competitive racing on Saturday at the Clásica San Sebastián, marking his first event in 141 days following a...

Sports

As the 2025 NFL season approaches, fantasy football enthusiasts are gearing up for their drafts, particularly focusing on tight ends. With players like Brock...

Health

Translucent, an innovative start-up specializing in artificial intelligence, has secured $7 million in seed funding to enhance its technology aimed at helping healthcare organizations...

Top Stories

California has taken a stand against a federal directive from the Trump administration demanding the exclusion of transgender athletes from girls’ and women’s sports....

Copyright © All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site.