HomeSecurityMicrosoft: Warns of cyberattacks on server software

Microsoft: Warns of cyberattacks on server software

Microsoft is sounding the alarm, warning of cyberattacks targeting server software, widely used by government agencies, state organizations and businesses for internal document and data movement. The attacks exploit a zero-day vulnerability, with the company calling for the immediate implementation of critical security updates.

Microsoft cyberattacks on server software

FBI – CISA: High-priority threat to public and private sectors

The FBI confirmed that it is aware of the attacks and is actively working with government and private partners to address them. While it did not provide further details, its joint action with CISA (Cybersecurity and Infrastructure Security Agency) and the US Department of Defense Cybersecurity Command shows the seriousness of the situation.

See also: BIND 9 vulnerabilities expose organizations to DoS attacks

According to a report by the Washington Post, the attacks on server software were carried out by unknown cybercriminals and hit US and international infrastructure. Experts estimate that tens of thousands of servers may be at risk. The US appears to be most affected, followed by the Netherlands, the UK and Canada.

Palo Alto Networks Inc.warned that “these exploits are real, readily available, and pose a serious threat.” Google’s Threat Intelligence Group said it had observed hackers exploiting the vulnerability, adding that it allows “persistent, unauthorized access and poses significant risk to affected organizations.”

The Washington Post reported that the breach had affected US federal and state agencies, universities, energy companies and an Asian telecommunications company.

What we know about vulnerability – Zero–day and spoofing

According to Microsoft's warning, the vulnerability could allow an authorized attacker to conduct a network spoofing attack. Such attacks allow the attacker to spoof their identity and appear as a trusted system or user, which could allow them to bypass security checks and gain access to sensitive data. Hackers can maintain access through backdoors or modified components that can survive system updates and reboots.

Microsoft clarified that SharePoint Online , which is hosted in Microsoft 365 (cloud-based) , is not affected by the vulnerability – at least for now. The problem only affects on -premises SharePoint servers .

See also: Cloudflare: Resolver 1.1.1.1 outage was not caused by an attack

SharePoint
Microsoft: Warns of cyberattacks on server software

What should system administrators do?

Microsoft says system administrators should apply the security updates immediately. For those who cannot enable the recommended defenses, it is recommended to temporarily disconnect servers from the internet.

The company has already issued guidance to its customers, emphasizing the immediate need to take preventive measures and install available patches. Otherwise, organizations risk becoming easy targets for sophisticated phishing attacks, which can lead to data theft, internal system compromise , and financial losses.

Threat context and political dimension

Attacks of this type (server software) may be part of a broader spectrum of state-directed or supported attacks, which is of particular concern to the United States and its allies. Vulnerable software used in government networks and military installations is a strategic target, especially in times of heightened geopolitical tensions.

See also: Q2 2025: Increased ransomware attacks in retail

The need for immediate action and strengthening cyber defense

This new attack is a stark reminder of the importance of prevention and vigilance in cybersecurity. System administrators and cybersecurity managers should apply updates promptly, monitor logs for suspicious activity, and review critical system isolation policies.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Microsoft assures that it is in constant communication with the Authorities and its customers worldwide, in order to ensure the maximum possible protection.

Source: Reuters

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS