Microsoft has issued a security alert on the weekend after detecting active cyber attacks by exploring a vulnerability on local SharePoint servers, a platform widely used by companies and governments for document sharing.
According to the company, the fault affects only on-prem servers-locally installed versions in organizations-leaving out the Microsoft 365 online sharepoint service, cloud-based. The recommendation is for customers to immediately apply security updates available.
Read more:
Enjoy!
NFL in Brazil: Extra Tickets

NFL Game in SP: With XP card you compete for 10 pairs of tickets
The breach allows authorized strikers to perform spoofingtechnique that masks the identity of the invader to pass a reliable user or service. In addition, according to the US Cyber and Infrastructure Security Agency (CISA), the attack can give access to file systems, internal settings and allow remote execution of malicious codes.
Cyber security companies, such as Palo Alto Networks and Google’s Threat Intelligence Division, have confirmed that attacks are being performed “in the real world” and have “significant risk” to affected organizations. Vulnerability also allows hackers to maintain access even after corrections apply through modified backdoors or components.
Researcher Silas Cutler, from Censory, estimated that more than 10,000 companies are vulnerable, with the highest concentration in the US, followed by the Netherlands, the United Kingdom and Canada. Eye Security, which initially identified the attack, said the failure allows the extraction of authentication keys, enabling digital identity forgery.
Continues after advertising
Invasions have already affected federal and state agencies from the US, universities, energy companies and an Asian telecommunications operator, according to the Washington Post. The FBI claimed to be aware of the attacks and acts together with federal agencies and the private sector.
Microsoft also advised that if it is not possible to apply recommended protective measures, customers disconnect internet servers until new updates are available.