Microsoft has issued security patches and will probably issue more after a major vulnerability was found in its Sharepoint software. Cody Combs / The National
Microsoft has issued security patches and will probably issue more after a major vulnerability was found in its Sharepoint software. Cody Combs / The National
Microsoft has issued security patches and will probably issue more after a major vulnerability was found in its Sharepoint software. Cody Combs / The National
Microsoft has issued security patches and will probably issue more after a major vulnerability was found in its Sharepoint software. Cody Combs / The National

US warns over Microsoft Sharepoint cyber vulnerability


Cody Combs
  • English
  • Arabic

A cyber security vulnerability in Microsoft's SharePoint collaboration software has been added to the US Cybersecurity and Infrastructure Security Agency exploitation list as customers deal with the potential fallout.

Computer security experts say hackers have exploited the loophole and potentially compromised private and public computer networks in the US.

The individual or group behind the software exploitation is not yet known.

“The incident reveals the growing sophistication of threat actors who have gained internal access to an environment and can now leverage existing resources (like Microsoft Exchange, SharePoint,) to conduct nefarious missions beyond just ransomware attacks, like 'wiper' malware that deletes data,” said Morey Haber, a chief security adviser at cyber security company BeyondTrust.

Mr Haber said Microsoft appears to have responded quickly once the vulnerability to Sharepoint was identified, but that for some, it might be too little, too late.

“Considering the speed of exploitation, some organisations may be waking up Monday morning to a fresh series of attacks,” he explained.

The various editions of Microsoft Sharepoint are also making it more difficult to provide a one-size-fits-all solution.

Microsoft said that it released a security update for SharePoint 2019, and that other fixes would be on the way.

“We are actively working on updates for SharePoint 2016,” the Redmond, Washington software company posted on X.

Santiago Pontiroli, lead researcher at cyber protection company Acronis, said: “This incident continues a trend of high-impact attacks against Microsoft infrastructure, including the Exchange mass exploitation in 2021 and the 2023 cloud email breach.

“Over the past several years, state-aligned and advanced persistent threat groups have repeatedly abused vulnerabilities in Microsoft platforms to gain initial access, steal sensitive data, and establish long-term footholds in enterprise networks.”

Microsoft does, however, invest heavily in trying to prevent such breaches from occurring.

Federal law enforcement agencies regularly work with the company and have a presence at its cyber crime centre in Redmond.

Cyber security is a continuing game of "whack-a-Mole", and that companies and organisations using Sharepoint should take it seriously," Mr Pontiroli said.

“Organisations still running on-premises SharePoint need to act now,” he said. “Apply the latest updates, monitor for signs of compromise, and assume exposure if systems were only partially patched.”

NO OTHER LAND

Director: Basel Adra, Yuval Abraham, Rachel Szor, Hamdan Ballal

Stars: Basel Adra, Yuval Abraham

Rating: 3.5/5

UAE currency: the story behind the money in your pockets
World record transfers

1. Kylian Mbappe - to Real Madrid in 2017/18 - €180 million (Dh770.4m - if a deal goes through)
2. Paul Pogba - to Manchester United in 2016/17 - €105m
3. Gareth Bale - to Real Madrid in 2013/14 - €101m
4. Cristiano Ronaldo - to Real Madrid in 2009/10 - €94m
5. Gonzalo Higuain - to Juventus in 2016/17 - €90m
6. Neymar - to Barcelona in 2013/14 - €88.2m
7. Romelu Lukaku - to Manchester United in 2017/18 - €84.7m
8. Luis Suarez - to Barcelona in 2014/15 - €81.72m
9. Angel di Maria - to Manchester United in 2014/15 - €75m
10. James Rodriguez - to Real Madrid in 2014/15 - €75m

The specs

Price: From Dh529,000

Engine: 5-litre V8

Transmission: Eight-speed auto

Power: 520hp

Torque: 625Nm

Fuel economy, combined: 12.8L/100km

The specs
  • Engine: 3.9-litre twin-turbo V8
  • Power: 640hp
  • Torque: 760nm
  • On sale: 2026
  • Price: Not announced yet
Updated: July 22, 2025, 6:41 AM`