Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



Trump Warns Iran Blockade Could Last Months, Sending Oil Prices Soaring

President Donald Trump speaks to reporters as he meets with NASA's Artemis II astronauts Victor Glover, Christina Koch, Reid Wiseman and Jeremy Hansen in the Oval Office of the White House, Wednesday, April 29, 2026, in Washington. (AP Photo/Matt Rourke)
President Donald Trump speaks to reporters as he meets with NASA's Artemis II astronauts Victor Glover, Christina Koch, Reid Wiseman and Jeremy Hansen in the Oval Office of the White House, Wednesday, April 29, 2026, in Washington. (AP Photo/Matt Rourke)
TT

Trump Warns Iran Blockade Could Last Months, Sending Oil Prices Soaring

President Donald Trump speaks to reporters as he meets with NASA's Artemis II astronauts Victor Glover, Christina Koch, Reid Wiseman and Jeremy Hansen in the Oval Office of the White House, Wednesday, April 29, 2026, in Washington. (AP Photo/Matt Rourke)
President Donald Trump speaks to reporters as he meets with NASA's Artemis II astronauts Victor Glover, Christina Koch, Reid Wiseman and Jeremy Hansen in the Oval Office of the White House, Wednesday, April 29, 2026, in Washington. (AP Photo/Matt Rourke)

President Donald Trump said a US naval blockade against Iran could last months, leading oil prices to spike to their highest level in more than four years, which held into Thursday.

Trump is expected to receive a briefing on Thursday on new plans for potential military action in Iran from Admiral Brad Cooper, the head of US Central Command, two sources with knowledge told Axios.

With diplomacy between Iran and the United States at a standstill after false starts, Trump spoke by phone Wednesday with Russian President Vladimir Putin, who warned him of "damaging consequences" if the United States and Israel resume their war on Iran.

Meeting oil executives, Trump contended that the blockade of Iranian ports -- which Tehran has demanded must end before any deal -- was more effective than bombing.

US Central Command (CENTCOM) said Wednesday on X that it had reached a "significant milestone after successfully redirecting the 42nd commercial vessel attempting to violate the blockade".

It said there are "41 tankers with 69 million barrels of oil that the Iranian regime can't sell", estimating the value at more than $6 billion.

Trump has faced intense political pressure to end the war, which is unpopular even with much of his base, having increased costs for American consumers and unnerved US allies.

Trump, speaking to Axios, said of the naval action on Iran: "They are choking like a stuffed pig. And it is going to be worse for them."

Oil prices soared to four-year highs, with US benchmark Brent spiking more than seven percent to $126.41 for June delivery, while West Texas Intermediate was up around three percent to $110.31. Both later pared the gains, AFP reported.

Top US officials including Vice President JD Vance twice turned back last week from trips to Pakistan to negotiate with Iran, which has voiced doubts about Trump's sincerity for diplomacy.

US officials contend they do not know who is speaking for Iran, whether it is the hardline and increasingly empowered Revolutionary Guards or diplomats, after Israeli strikes killed a series of top leaders.

Iran has proposed easing its chokehold over the Strait of Hormuz as Washington lifts its blockade and broader negotiations take place. The Trump administration has been skeptical of the proposal.

Iran's parliament speaker Mohammad Bagher Ghalibaf, who has emerged as a key figure since the start of the war, said Wednesday the US naval blockade of the country aimed to create division and "make us collapse from within".


Grossi: Iran's Highly Enriched Uranium Likely is at Isfahan Site

Rafael Grossi, International Atomic Energy Agency (IAEA) Director General and a candidate for United Nations Secretary-General, speaks during an interview at UN headquarters, Tuesday, April 28, 2026. (AP Photo/Yuki Iwamura)
Rafael Grossi, International Atomic Energy Agency (IAEA) Director General and a candidate for United Nations Secretary-General, speaks during an interview at UN headquarters, Tuesday, April 28, 2026. (AP Photo/Yuki Iwamura)
TT

Grossi: Iran's Highly Enriched Uranium Likely is at Isfahan Site

Rafael Grossi, International Atomic Energy Agency (IAEA) Director General and a candidate for United Nations Secretary-General, speaks during an interview at UN headquarters, Tuesday, April 28, 2026. (AP Photo/Yuki Iwamura)
Rafael Grossi, International Atomic Energy Agency (IAEA) Director General and a candidate for United Nations Secretary-General, speaks during an interview at UN headquarters, Tuesday, April 28, 2026. (AP Photo/Yuki Iwamura)

The majority of Iran’s highly enriched uranium is likely still at its Isfahan nuclear complex, which was bombarded by airstrikes last year and faced less intense attacks in this year’s US-Israeli war, the UN nuclear agency’s leader.

Rafael Grossi told The Associated Press on Tuesday that the International Atomic Energy Agency has satellite images showing the effects of the latest US-Israeli airstrikes against Iran and that “we continue to get information.”

IAEA inspections ended at Isfahan when Israel last June launched a 12-day war that saw the United States bomb three Iranian nuclear sites.

The UN nuclear watchdog believes a large percentage of Iran’s highly enriched uranium “was stored there in June 2025 when the 12-day war broke out, and it has been there ever since,” Grossi said.

“We haven’t been able to inspect or to reject that the material is there and that the seals — the IAEA seals — remain there,” he said. “I hope we’ll be able to do that, so what I tell you is our best estimate.”

Images from an Airbus satellite show a truck loaded with 18 blue containers going into a tunnel at the Isfahan Nuclear Technology Center on June 9, 2025, just before last year’s war started. Those containers, believed to contain highly enriched uranium, likely remain there.

All Iran’s nuclear sites must be inspected

The IAEA also wants to inspect Iran’s nuclear facilities at Natanz and Fordo, where there is also some nuclear material, the IAEA director general added.

Iran is a party to the Nuclear Nonproliferation Treaty, whose five-year review is underway at UN headquarters. Under its provisions, Iran is required to open its nuclear facilities to IAEA inspection, Grossi said.

Iran has 440.9 kilograms of uranium that is enriched up to 60% purity, a short, technical step from weapons-grade levels of 90%, according to the agency. Grossi has said the IAEA believes roughly 200 kilograms is stored in tunnels at the Isfahan site.

The Iranian stockpile could allow the country to build as many as 10 nuclear bombs, should it decide to weaponize its program, Grossi told AP last year.

Tehran long has insisted its nuclear program is peaceful. US President Donald Trump said one of the major reasons the US went to war was to deny Iran the ability to develop nuclear weapons, even as he has insisted that the strikes last summer “obliterated” the country’s atomic program.

Last Saturday, The New York Times reported that Iran has a total of 11 tons of uranium, at various enrichment levels. A nuclear expert told the newspaper that Iran’s stockpile could yield roughly 35 to 55 weapons depending on its skill in making not only the bomb’s fuel core but such nonnuclear parts as detonators that spark the chain reactions. Another expert said Iran’s stockpile was sufficient for 50 to 100 bombs if further enriched.

Taking the highly enriched uranium out of Iran

Grossi said the IAEA has discussed with Russia and others the possibility of sending Iran’s highly enriched uranium out of the country — a complex operation that would require either a political agreement or a major US military operation in hostile territory.

Grossi noted that “what’s going to be important is that that material leaves Iran” or is blended to reduce its enrichment.

He said the IAEA participated in US-Iran nuclear talks in February but has not been part of recent ceasefire negotiations mediated by Pakistan. He said the agency has been in discussions separately with the US and informally with Iran.

The IAEA chief said negotiations now are a “completely different ballgame” because of Iran’s “exponential progress” not only on enriching uranium but using the latest generation of centrifuges, different compounds and new facilities.

‘Political will’

It would take “political will” from Tehran to reach a deal, Grossi told AP, stressing that “Iran has to be convinced that it is important to negotiate.”

Iran’s leaders say they are willing to negotiate and so does the Republican US president, Grossi said, but “where the frustration kicks in, apparently for both, is that they do not seem to come to agreement, or be at an eye-to-eye level, on what needs to be done first, or on how.”

Calling himself a negotiator who likes to see a “flicker of hope,” Grossi noted that “one important thing is that there is apparently an interest on both sides to come to an agreement.”

Asked if he thinks the Iranians are serious about making a deal, Secretary of State Marco Rubio told Fox News Channel this week that they are skilled negotiators looking to buy time and that any agreement must be “one that definitively prevents them from sprinting towards a nuclear weapon at any point.”


USS Ford Aircraft Carrier Departs Middle East after Record-breaking Deployment

The US Navy aircraft carrier USS Gerald R. Ford departs Souda Bay on the island of Crete on February 26, 2026. (Photo by Costas METAXAKIS / AFP)
The US Navy aircraft carrier USS Gerald R. Ford departs Souda Bay on the island of Crete on February 26, 2026. (Photo by Costas METAXAKIS / AFP)
TT

USS Ford Aircraft Carrier Departs Middle East after Record-breaking Deployment

The US Navy aircraft carrier USS Gerald R. Ford departs Souda Bay on the island of Crete on February 26, 2026. (Photo by Costas METAXAKIS / AFP)
The US Navy aircraft carrier USS Gerald R. Ford departs Souda Bay on the island of Crete on February 26, 2026. (Photo by Costas METAXAKIS / AFP)

The world's largest aircraft carrier, the USS Gerald R. Ford, will be heading home following a record-setting deployment of more than 300 days that included participating in the war against Iran and capture of Venezuelan leader Nicolás Maduro, two US officials said Wednesday.

The Ford will be leaving the Middle East in the coming days and returning to its home port in Virginia in mid-May, according to the officials, who spoke on condition of anonymity to detail sensitive military movements. The Washington Post reported the development earlier.

The arrival of the USS George H.W. Bush to the region last week meant three American aircraft carriers were deployed to the Middle East — a number not seen since 2003 — during a tenuous ceasefire in the Iran war. USS Abraham Lincoln also has been in the region since January as tensions with Tehran ramped up.

This month, the Ford broke the US record for the longest post-Vietnam War deployment, a nearly 10-month span after leaving Naval Station Norfolk in June, The Associated Press reported.

The ship’s 295th day at sea surpassed the previous longest deployment by an aircraft carrier in the past 50 years, when the Lincoln was sent out for 294 days in 2020 during the COVID-19 pandemic, according to data compiled by US Naval Institute News, a news outlet run by the US Naval Institute, a nonprofit organization.

The Ford's long deployment has raised questions about the impact on service members who are away from home for long periods as well as increasing strain on the ship and its equipment, with the carrier already enduring a fire that forced it to undergo lengthy repairs.

Asked about the Ford's long deployment in a hearing Wednesday before the House Armed Services Committee, Defense Secretary Pete Hegseth said he consulted with the Navy and those officials did mention readiness and maintenance tradeoffs.

"Multiple times the operational requirements — whether it was down in Southcom or up to Centcom — demanded additional assets in real time, which through a tough decision-making process led to an extension,” Hegseth said, referring to US Southern Command, which oversees Latin America, and US Central Command in the Middle East.

The Ford began its deployment by heading to the Mediterranean Sea. It was then rerouted to the Caribbean Sea in October as part of the largest naval buildup in the region in generations.

The carrier took part in the military operation to capture Maduro. Then it would see more battle, heading toward the Middle East as tensions with Iran escalated.

The carrier took part in the opening days of the Iran war from the Mediterranean Sea before going through the Suez Canal and heading into the Red Sea in early March.

However, a fire in one of its laundry spaces forced the carrier to turn around and return to the Mediterranean Sea for repairs, leaving hundreds of sailors without places to sleep.

The Ford’s 295-day deployment falls short of the longest deployment during the Cold War, a record held by the now-decommissioned USS Midway. It was deployed for 332 days in 1972 and 1973.

More recently, the crew of the USS Nimitz was on duty and away from home for a total of 341 days in 2020 and 2021. However, that included extended isolation periods ashore in the US meant to help prevent the spread of COVID-19.