CRIME BLOTTER

Microsoft issues warning after hackers exploit unknown SharePoint flaw

Jul 21, 2025, 1:26 PM

A warning has been issued to Microsoft users detailing a cybersecurity flaw that allowed hackers to access its SharePoint servers, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced.

The CISA posted an alert on Sunday, which said it is aware of an “active exploitation” that enables unauthorized access to on-site SharePoint servers, and is continuing to monitor the severity of the situation.

Microsoft SharePoint hack

Microsoft SharePoint is a platform used for document management that allows users to share files, data, and track project status. SharePoint is also integrated with Microsoft 365 applications, including Teams and OneDrive.

The hack is labeled as a “zero-day” attack due to the previously unknown vulnerability within the system, and tens of thousands of servers were at risk, according to Reuters.

In an alert posted by Microsoft on July 19, the company said that the exploit enables an “authorized attacker to perform spoofing over a network.” A spoofing cyberattack involves an actor manipulating financial markets or agencies by hiding their identity and tricking a user into believing that they are a trusted source.

“We’ve been coordinating closely with CISA, DOD Cyber Defense Command, and key cybersecurity partners globally throughout our response,” a Microsoft spokesperson said, according to Reuters.

Microsoft noted that the vulnerabilities solely applied to SharePoint servers used within organizations. SharePoint Online in Microsoft 365, which is in the cloud, was not involved in the attack.

“The FBI is aware of the matter, and we are working closely with our federal government and private sector partners,” a Microsoft spokesperson told USA TODAY.

Microsoft told its customers that if they can’t enable recommended malware protection, they should disconnect their servers from the internet until a security update becomes available, according to Reuters.

Follow Jason Sutich on X. Send news tips here.

Crime Blotter

tacoma grocery store owner...

Aaron Granillo

Tacoma grocery store owner added to FBI’s Most Wanted Fraudsters list

A Tacoma grocery store owner accused of stealing more than $600,000 has been added to the FBI's Most Wanted Fraudsters list.

14 hours ago

hammer attack suspect...

James Lynch

Prosecutors file attempted murder charge in downtown Seattle hammer attack

King County prosecutors have charged Bey Mateen Muhammed, 23, with attempted murder in a hammer attack in Seattle.

17 hours ago

Puyallup Police car...

MyNorthwest Staff

Driver arrested for DUI after hitting pedestrian in Puyallup

A driver was arrested for alleged DUI after reportedly hitting a pedestrian in Puyallup.

19 hours ago

Portland pedophile stab child...

MyNorthwest Staff

‘I stabbed a pedophile’: Portland man sentenced to 5 years after stabbing man he says sent him child sexual abuse material

A Portland man stabbed a 46-year-old man, Joshua Field, whom he met on a dating site last summer because Field had sent him child sexual abuse material.

21 hours ago

big 5 renton sentenced shooting...

KIRO 7 News Staff

Man sentenced to more than 25 years for shooting, killing teen outside Big 5 in Renton

A man who shot and killed a teenager outside the Big 5 Sporting Goods Store in Renton two summers ago has been sentenced to more than 25 years in prison.

1 day ago

seattle rapper kill cold case...

James Lynch

Cold Case: Family pleads for answers in killing of North Seattle rapper ‘Lavish Rich’

Nearly three years after 31-year-old father and local rapper Cornel Callandret Jr. was gunned down in Seattle, his family and fans still wait for answers.

1 day ago

Microsoft issues warning after hackers exploit unknown SharePoint flaw