Microsoft urgently patched a zero-day vulnerability in its SharePoint software exploited by hackers targeting businesses and US government agencies. The exploit, potentially known as "ToolShell," allows full access to SharePoint file systems, impacting on-site servers (not cloud-based SharePoint Online). Cybersecurity firms like CrowdStrike and Palo Alto Networks warn of widespread risk, especially for government, schools, healthcare, and large enterprises. Microsoft advises immediate patching and disconnection of affected servers until patched, while CISA urges similar action and cryptographic material rotation.
Prepared by Jonathan Pierce and reviewed by editorial team.
Comments