Close Menu
John Mahama News
  • Home
  • Ghana News
  • Anti-Corruption
    • Corruption Watch
  • Economic
    • Education & Innovation
  • Environmental
    • Governance & Policy
  • Health & Welfare
    • Historical & Cultural Insights
    • Infrastructure & Development
    • International Relations
  • Ministerial News
    • Presidential Updates
  • Public Opinion
    • Regional Governance
      • Social Issues & Advocacy
      • Youth & Sports
What's Hot

REMAPSEN and Galien Africa partner to boost health and environmental communication

July 23, 2025

The Leader and Hope Ghana Deserves.

July 23, 2025

Ashanti Region Kusasi Chief shot dead by unknown assailants

July 23, 2025
Facebook X (Twitter) Instagram
Trending
  • REMAPSEN and Galien Africa partner to boost health and environmental communication
  • The Leader and Hope Ghana Deserves.
  • Ashanti Region Kusasi Chief shot dead by unknown assailants
  • Prices of some imported goods could be reduced in coming weeks – GIFF assures
  • 23-year-old woman kills son at Karlo to please lover
  • Trump administration releases files on Martin Luther King Jr
  • God Bless President John Dramani Mahama — Ghana’s Leader of True Transformation
  • The Supreme Court’s ruling on Kevin Taylor’s arrest warrant: A triumph for due process or a precedent for judicial caution?
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
John Mahama News
Wednesday, July 23
  • Home
  • Ghana News
  • Anti-Corruption
    • Corruption Watch
  • Economic
    • Education & Innovation
  • Environmental
    • Governance & Policy
  • Health & Welfare
    • Historical & Cultural Insights
    • Infrastructure & Development
    • International Relations
  • Ministerial News
    • Presidential Updates
  • Public Opinion
    • Regional Governance
      • Social Issues & Advocacy
      • Youth & Sports
John Mahama News
Home » Microsoft knew of SharePoint server exploit but failed to effectively patch it

Microsoft knew of SharePoint server exploit but failed to effectively patch it

johnmahamaBy johnmahamaJuly 22, 2025 Infrastructure & Development No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


A security patch released by Microsoft last month failed to fully fix a critical flaw in U.S. tech giant’s SharePoint server software that had been identified in May, opening the door to a sweeping global cyber espionage operation.

It remains unclear who is behind the ongoing operation, which targeted around 100 organisations over the weekend. But Alphabet’s Google, which has visibility into wide swathes of internet traffic, said it tied at least some of the hacks to a “China-nexus threat actor”.

The Chinese Embassy in Washington did not respond to a Reuters request for comment. Chinese government-linked operatives are regularly implicated in cyberattacks, but Beijing routinely denies carrying out hacking operations.

Contacted on Tuesday, Microsoft was not immediately able to provide comment on the patch and its effectiveness.

The vulnerability that facilitated the attack was first identified in May at a hacking competition in Berlin organised by cybersecurity firm Trend Micro which offered cash bounties for the discovery of computer bugs in popular software.

It offered a $100,000 prize for “zero day” exploits – so called because they leverage previously undisclosed digital weaknesses – that could be used against SharePoint, Microsoft’s flagship document management and collaboration platform.

A researcher working for the cybersecurity arm of Viettel, a telecommunications firm operated by Vietnam’s military, identified, opens new tab a SharePoint bug at the event, dubbed it ‘ToolShell’ and demonstrated a method of exploiting it.

The researcher was awarded $100,000 for the discovery, according to a post, opens new tab on X by Trend Micro’s “Zero Day Initiative”. A spokesperson for Trend Micro did not immediately respond to Reuters’ requests for comment regarding the competition on Tuesday.

Microsoft subsequently said in a July 8 security update that it had identified, opens new tab the bug, listed it as a critical vulnerability, and released patches to fix it.

Around 10 days later, however, cybersecurity firms started to notice an influx of malicious online activity targeting the same software the bug sought to exploit: SharePoint servers.

“Threat actors subsequently developed exploits that appear to bypass these patches,” British cybersecurity firm Sophos said in a blog post, on Monday.

The pool of potential ToolShell targets remains vast.

According to data from Shodan, a search engine that helps to identify internet-linked equipment, over 8,000 servers online could theoretically have already been compromised by hackers.

The Shadowserver Foundation, which scans the internet for potential digital vulnerabilities, put the number at a little more than 9,000, while cautioning that the figure was a minimum.

Those servers include major industrial firms, banks, auditors, healthcare companies, and several U.S. state-level and international government entities.

DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.

DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.



Source link

johnmahama
  • Website

Keep Reading

Prices of some imported goods could be reduced in coming weeks – GIFF assures

OpenAI and UK sign deal to use AI in public services

Irish government reveals how Apple tax windfall will be spent

Ho Technical University partners with GhIE Branch 6 For Engineering and Innovation Week

School under siege – Why cybersecurity must be a top priority in Ghanaian classrooms

Newmont completes GH₵ 95m Hwidiem–Kenyasi road; commits $34m to boost Ahafo South infrastructure

Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Chinese firms explore opportunities under Ghana’s 24- Hour Economy programme

July 22, 2025

BoG issues guidelines on exchange rate application in shipping sector

July 22, 2025

A win for gov’t borrowing, but will it last?

July 22, 2025

Is there really a forex shortage, or industry players are hoarding it?

July 22, 2025
Latest Posts

Infinix HOT 60 Pro+ officially launches, setting a new global record for the world’s slimmest 3D-curved screen phone

July 21, 2025

Ghana ready to partner ECOWAS in fight against money laundering — Foreign Affairs Ministry

July 17, 2025

GIABA rallies ECOWAS Resident Representatives to step up anti-money laundering efforts

July 17, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Welcome to JohnMahama.news, your trusted source for the latest news, insights, and updates about the President of Ghana, government policies, and the nation at large. Our mission is to provide accurate, timely, and comprehensive coverage of all things related to the leadership of Ghana, as well as key national issues that impact citizens and communities across the country.

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
© 2025 johnmahama. Designed by johnmahama.

Type above and press Enter to search. Press Esc to cancel.