CRIME BLOTTER

Microsoft issues warning after hackers exploit unknown SharePoint flaw

Jul 21, 2025, 1:26 PM

A warning has been issued to Microsoft users detailing a cybersecurity flaw that allowed hackers to access its SharePoint servers, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced.

The CISA posted an alert on Sunday, which said it is aware of an “active exploitation” that enables unauthorized access to on-site SharePoint servers, and is continuing to monitor the severity of the situation.

Microsoft SharePoint hack

Microsoft SharePoint is a platform used for document management that allows users to share files, data, and track project status. SharePoint is also integrated with Microsoft 365 applications, including Teams and OneDrive.

The hack is labeled as a “zero-day” attack due to the previously unknown vulnerability within the system, and tens of thousands of servers were at risk, according to Reuters.

In an alert posted by Microsoft on July 19, the company said that the exploit enables an “authorized attacker to perform spoofing over a network.” A spoofing cyberattack involves an actor manipulating financial markets or agencies by hiding their identity and tricking a user into believing that they are a trusted source.

“We’ve been coordinating closely with CISA, DOD Cyber Defense Command, and key cybersecurity partners globally throughout our response,” a Microsoft spokesperson said, according to Reuters.

Microsoft noted that the vulnerabilities solely applied to SharePoint servers used within organizations. SharePoint Online in Microsoft 365, which is in the cloud, was not involved in the attack.

“The FBI is aware of the matter, and we are working closely with our federal government and private sector partners,” a Microsoft spokesperson told USA TODAY.

Microsoft told its customers that if they can’t enable recommended malware protection, they should disconnect their servers from the internet until a security update becomes available, according to Reuters.

Follow Jason Sutich on X. Send news tips here.

Crime Blotter

Ballard hit-and-run...

KIRO Newsradio staff

20-year-old sentenced to more than 3 years for deadly 2025 Ballard hit-and-run

The man accused in the hit-and-run death of a pedestrian in Ballard last year has been sentenced to more than three years in prison.

2 days ago

2 box truck fire SODO...

Julia Dallas

Suspects accidentally light themselves on fire while allegedly trying to steal fuel from box trucks in SODO

Two suspects accidentally set themselves on fire while they appeared to be trying to steal fuel from box trucks in the SODO neighborhood.

2 days ago

columbia city school gun...

MyNorthwest Staff

Person in custody after gun seized by staff at high school in Seattle

A person is in custody after a gun was seized by staff at a high school in Seattle.

2 days ago

Arlington police...

MyNorthwest Staff

Arlington police seize pellet gun at middle school

Arlington police are investigating a report that a student may have had a gun at Haller Middle School.

3 days ago

thurston county sex offender chase...

Jack Bilyeu, KIRO 7 News

Wanted sex offender arrested in Thurston County after brief chase

A convicted felon who failed to register as a sex offender was arrested in Thurston County Wednesday night.

3 days ago

k9 portland officer-involved shooting...

Frank Sumrall

Portland police K9 Kylo killed in officer-involved shooting on what was supposed to be the dog’s last shift

A K9 with the Portland Police Bureau was killed in an officer-involved shooting Thursday that resulted in the suspect's death.

3 days ago

Microsoft issues warning after hackers exploit unknown SharePoint flaw