³ÉÈËXÕ¾

MYNORTHWEST NEWS

Microsoft issues warning after hackers exploit unknown SharePoint flaw

Jul 21, 2025, 1:26 PM

Microsoft SharePoint hack...

A photo of the Microsoft logo. (Photo: David Ramos, Getty Images)

(Photo: David Ramos, Getty Images)

A warning has been issued to Microsoft users detailing a cybersecurity flaw that allowed hackers to access its SharePoint servers, the U.S. Cybersecurity and Infrastructure Security Agency .

The CISA posted an alert on Sunday, which said it is aware of an “active exploitation” that enables unauthorized access to on-site SharePoint servers, and is continuing to monitor the severity of the situation.

Microsoft SharePoint hack

Microsoft SharePoint is a platform used for document management that allows users to share files, data, and track project status. SharePoint is also integrated with Microsoft 365 applications, including Teams and OneDrive.

The hack is labeled as a “zero-day” attack due to the previously unknown vulnerability within the system, and tens of thousands of servers were at risk, according to .

In an alert posted by Microsoft on July 19, the company said that the exploit enables an “authorized attacker to perform spoofing over a network.” A spoofing cyberattack involves an actor manipulating financial markets or agencies by hiding their identity and tricking a user into believing that they are a trusted source.

“We’ve been coordinating closely with CISA, DOD Cyber Defense Command, and key cybersecurity partners globally throughout our response,” a Microsoft spokesperson said, according to Reuters.

Microsoft noted that the vulnerabilities solely applied to SharePoint servers used within organizations. SharePoint Online in Microsoft 365, which is in the cloud, was not involved in the attack.

“The FBI is aware of the matter, and we are working closely with our federal government and private sector partners,” a Microsoft spokesperson told .

Microsoft told its customers that if they can’t enable recommended malware protection, they should disconnect their servers from the internet until a security update becomes available, according to Reuters.

Follow Jason Sutich .Ìý³§±ð²Ô»åÌýnews tips here.

MyNorthwest News

man in awning belltown...

MyNorthwest Staff

SPD responds to man refusing to come down from awning in Belltown

Seattle Police dealt with a man refusing to come down from a awning in Belltown.

23 minutes ago

renton shooting...

Frank Sumrall

Bail set at $10 million for suspect in Renton triple homicide case

A suspect was arrested less than a day after three people were killed in a shooting in a Renton neighborhood, the Renton Police Department confirmed.

41 minutes ago

measles (1)...

Heather Bosch

Travel warning: Measles cases at highest since virus was considered eradicated

Over 1,300 measles cases reported in the U.S. this year, raising alarm as rates reach the highest since the virus was deemed eradicated.

48 minutes ago

Leonard Thomas pierce county...

Frank Lenzi

2013 fatal police shooting referred to Pierce County Prosecutor’s Office for new investigation

A decade later, the case of Leonard Thomas' police shooting is referred to Pierce County prosecutors for further examination.

2 hours ago

cougar attack...

Julia Dallas

4-year-old in hospital after cougar attack in Olympic National Park

A four-year-old is hospitalized after a cougar attack in Olympic National Park.

2 hours ago

pumpkin spice latte starbucks...

Frank Sumrall

Starbucks reveals return date for its pumpkin spice latte — one month before fall begins

Despite it still being summer, Starbucks is already ready for the autumn season after revealing the return of its famous pumpkin spice latte to the menu.

2 hours ago

Microsoft issues warning after hackers exploit unknown SharePoint flaw