Vietnam.vn - Nền tảng quảng bá Việt Nam

Warning of risks from "zero-day" vulnerabilities in Microsoft software

International cybersecurity organizations announced on July 21 that this large-scale attack had penetrated the systems of about 100 different organizations, including many businesses and government agencies.

VietnamPlusVietnamPlus22/07/2025

Experts are particularly concerned after Microsoft warned of a serious "zero-day" vulnerability in its SharePoint server software that could be exploited by hackers to attack systems used by many government agencies and businesses to share internal documents.

"Anyone who has a SharePoint server hosted externally is at risk," said Adam Meyers, senior vice president at cybersecurity firm CrowdStrike, adding that the vulnerability was "a serious one."

The vulnerability — also known as “ToolShell” — is a variant of the existing vulnerability CVE-2025-49706, according to the US Cybersecurity and Infrastructure Security Agency (CISA).

This vulnerability poses a risk to organizations with on-premises SharePoint servers, allowing hackers to gain full access to SharePoint file systems, including connected services like Teams and OneDrive.

Google's Cybersecurity Threat Analysis division also warned that the vulnerability could allow hackers to "bypass future patches."

Microsoft confirmed that its cloud-based SharePoint Online service is not affected by this vulnerability.

However, Michael Sikorski, CTO and head of threat analysis for Palo Alto Networks' Unit 42 Security Research Group, warns that the vulnerability still puts many organizations and individuals at risk. "While cloud environments are not affected, on-premises SharePoint deployments – especially in government, schools, healthcare , and large enterprise companies – are at immediate risk," he explains.

International cybersecurity organizations announced on July 21 that this large-scale attack had penetrated the systems of about 100 different organizations, including many businesses and government agencies.

Vaisha Bernard, a senior hacker at Dutch cybersecurity firm Eye Security, who discovered the attack on one of its clients on July 18, said the company had scanned more than 80,000 SharePoint servers worldwide with security firm Shadowserver Foundation and found nearly 100 victims. The expert declined to identify the affected organizations, but said relevant agencies and countries had been notified.

Shadowserver Foundation revealed that most of the affected organizations were in the US and Germany, including government organizations.

Meanwhile, the UK National Cyber Security Centre also announced that it had information about "a limited number" of targets in the country.

While the scope and extent of the attack are still being assessed, CISA warns that the impact could be widespread. The agency recommends that any servers affected by the vulnerability be disconnected from the internet until they are patched./.

(Vietnam News Agency/Vietnam+)

Source: https://www.vietnamplus.vn/canh-bao-nguy-co-tu-lo-hong-zero-day-trong-phan-mem-cua-microsoft-post1051061.vnp


Comment (0)

No data
No data
It took Vo Ha Tram 6 weeks to complete the music project praising the Fatherland.
Hanoi coffee shop is bright with red flags and yellow stars to celebrate the 80th anniversary of National Day September 2nd
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground
Watch helicopters rehearse in the sky of Hanoi in preparation for National Day September 2
U23 Vietnam radiantly brought home the Southeast Asian U23 Championship trophy
Northern islands are like 'rough gems', cheap seafood, 10 minutes by boat from the mainland
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony
S-300PMU1 missiles on combat duty to protect Hanoi's sky

Heritage

Figure

Business

No videos available

News

Political System

Local

Product