Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



Russia: Man Suspected of Shooting Top General Detained in Dubai

An investigator works outside a residential building where the assassination attempt on Russian Lieutenant General Vladimir Alexeyev took place in Moscow, Russia February 6, 2026. REUTERS/Anastasia Barashkova
An investigator works outside a residential building where the assassination attempt on Russian Lieutenant General Vladimir Alexeyev took place in Moscow, Russia February 6, 2026. REUTERS/Anastasia Barashkova
TT

Russia: Man Suspected of Shooting Top General Detained in Dubai

An investigator works outside a residential building where the assassination attempt on Russian Lieutenant General Vladimir Alexeyev took place in Moscow, Russia February 6, 2026. REUTERS/Anastasia Barashkova
An investigator works outside a residential building where the assassination attempt on Russian Lieutenant General Vladimir Alexeyev took place in Moscow, Russia February 6, 2026. REUTERS/Anastasia Barashkova

Russia's Federal Security Service (FSB) said on Sunday that the man suspected of shooting top Russian military intelligence officer Vladimir Alexeyev in Moscow has been detained in Dubai and handed over to Russia.

Lieutenant General Vladimir Alexeyev, deputy head of the GRU, ⁠Russia's military intelligence arm, was shot several times in an apartment block in Moscow on Friday, investigators said. He underwent surgery after the shooting, Russian media ⁠said.

The FSB said a Russian citizen named Lyubomir Korba was detained in Dubai on suspicion of carrying out the shooting.

Russian Foreign Minister Sergei Lavrov accused Ukraine of being behind the assassination attempt, which he said was designed to sabotage peace talks. ⁠Ukraine said it had nothing to do with the shooting.

Alexeyev's boss, Admiral Igor Kostyukov, the head of the GRU, has been leading Russia's delegation in negotiations with Ukraine in Abu Dhabi on security-related aspects of a potential peace deal.


Factory Explosion Kills 8 in Northern China

Employees work on an electric vehicle (EV) production line at the Volkswagen Anhui factory in Hefei, Anhui province, China, February 4, 2026. REUTERS/Florence Lo
Employees work on an electric vehicle (EV) production line at the Volkswagen Anhui factory in Hefei, Anhui province, China, February 4, 2026. REUTERS/Florence Lo
TT

Factory Explosion Kills 8 in Northern China

Employees work on an electric vehicle (EV) production line at the Volkswagen Anhui factory in Hefei, Anhui province, China, February 4, 2026. REUTERS/Florence Lo
Employees work on an electric vehicle (EV) production line at the Volkswagen Anhui factory in Hefei, Anhui province, China, February 4, 2026. REUTERS/Florence Lo

An explosion at a biotech factory in northern China has killed eight people, Chinese state media reported Sunday, increasing the total number of fatalities by one.

State news agency Xinhua had previously reported that seven people died and one person was missing after the Saturday morning explosion at the Jiapeng biotech company in Shanxi province, citing local authorities.

Later, Xinhua said eight were dead, adding that the firm's legal representative had been taken into custody.

The company is located in Shanyin County, about 400 kilometers west of Beijing, AFP reported.

Xinhua said clean-up operations were ongoing, noting that reporters observed dark yellow smoke emanating from the site of the explosion.

Authorities have established a team to investigate the cause of the blast, the report added.

Industrial accidents are common in China due to lax safety standards.
In late January, an explosion at a steel factory in the neighboring province of Inner Mongolia left at least nine people dead.


Iran Warns Will Not Give Up Enrichment Despite US War Threat

Traffic moves through a street in Tehran on February 7, 2026. (Photo by ATTA KENARE / AFP)
Traffic moves through a street in Tehran on February 7, 2026. (Photo by ATTA KENARE / AFP)
TT

Iran Warns Will Not Give Up Enrichment Despite US War Threat

Traffic moves through a street in Tehran on February 7, 2026. (Photo by ATTA KENARE / AFP)
Traffic moves through a street in Tehran on February 7, 2026. (Photo by ATTA KENARE / AFP)

Iran will never surrender the right to enrich uranium, even if war "is imposed on us,” its foreign minister said Sunday, defying pressure from Washington.

"Iran has paid a very heavy price for its peaceful nuclear program and for uranium enrichment," Abbas Araghchi told a forum in Tehran.

"Why do we insist so much on enrichment and refuse to give it up even if a war is imposed on us? Because no one has the right to dictate our behavior," he said, two days after he met US envoy Steve Witkoff in Oman.

The foreign minister also declared that his country was not intimidated by the US naval deployment in the Gulf.

"Their military deployment in the region does not scare us," Araghchi said.