Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



Trump to Attend Ceremony to Witness Return of US Personnel Killed in Syria

US President Donald Trump speaks to the media - Reuters
US President Donald Trump speaks to the media - Reuters
TT

Trump to Attend Ceremony to Witness Return of US Personnel Killed in Syria

US President Donald Trump speaks to the media - Reuters
US President Donald Trump speaks to the media - Reuters

US President Donald Trump and first lady Melania Trump will attend a ceremony on Wednesday to honor US personnel killed in Syria over the weekend by a suspected ISIS attacker.

Trump and his wife will travel to Dover Air Force Base in Delaware to be present for what the Air Force calls the "dignified transfer" of the bodies from overseas back into the United States in the presence of their families. The ceremony is scheduled to take place at 1:15 p.m. EST (1815 GMT), Reuters reported.

Two US Army soldiers and a civilian interpreter were killed on Saturday in the central Syrian town of Palmyra by an attacker who targeted a convoy of American and Syrian forces before being shot dead, according to the U.S. military.

Trump called the incident terrible, vowed retaliation and referred to the three that were slain as "great patriots."

Three US soldiers were also wounded in the attack.

US presidents, vice presidents and dignitaries regularly attend the solemn transfer ceremonies at Dover during times of war or conflict that result in the deaths of US troops. Flag-draped transfer cases are brought off of a military plane with the bodies of the fallen and put with precision in an awaiting vehicle as officials and family members watch and often weep.


Putin Says Russia will Achieve War Goals, Keep Expanding 'Buffer Zone'

Russian President Vladimir Putin attends a meeting with Kazbek Kokov, head of the North Caucasus region of Kabardino-Balkaria, in Moscow, Russia December 16, 2025. Sputnik/Mikhail Metzel/Pool via REUTERS
Russian President Vladimir Putin attends a meeting with Kazbek Kokov, head of the North Caucasus region of Kabardino-Balkaria, in Moscow, Russia December 16, 2025. Sputnik/Mikhail Metzel/Pool via REUTERS
TT

Putin Says Russia will Achieve War Goals, Keep Expanding 'Buffer Zone'

Russian President Vladimir Putin attends a meeting with Kazbek Kokov, head of the North Caucasus region of Kabardino-Balkaria, in Moscow, Russia December 16, 2025. Sputnik/Mikhail Metzel/Pool via REUTERS
Russian President Vladimir Putin attends a meeting with Kazbek Kokov, head of the North Caucasus region of Kabardino-Balkaria, in Moscow, Russia December 16, 2025. Sputnik/Mikhail Metzel/Pool via REUTERS

President Vladimir Putin said on Wednesday that Russia would achieve its goals in Ukraine by diplomatic or military means, and would seek to expand a "security buffer zone" there.

"First, the goals of the special military operation will undoubtedly be achieved. We would prefer to do this and address the root causes of the conflict through diplomacy," Putin said.

"If the opposing side and their foreign patrons refuse to engage in substantive discussions, Russia will achieve the liberation of its historical lands by military means. The task of creating and expanding a security buffer zone will also be consistently addressed."

Of the regions of Ukraine that Russia has claimed as its own territory, it currently controls Crimea, around 90% of the Donbas region and 75% of Kherson and Zaporizhzhia, Reuters reported.

In addition, Russia holds some territory in the adjoining regions of Kharkiv, Sumy, Dnipropetrovsk and Mykolaiv. Putin's comments signalled that Moscow would seek further gains on some of these fronts.

With the war at a key juncture as US President Donald Trump pushes hard for a quick peace agreement, Putin said Russia was advancing on all fronts.

But his defense minister, Andrei Belousov, acknowledged that Ukrainian forces were trying to take back control of the northeastern town of Kupiansk - an effort he said was not succeeding.

Ukraine said on Wednesday it had taken 90% of the town, which Russia said it had captured in November.

Putin said people in Europe were being indoctrinated with fears of a war with Russia, and accused their leaders of whipping up hysteria.

"I have repeatedly stated: this is a lie, nonsense, pure nonsense about some imaginary Russian threat to European countries. But this is being done quite deliberately," he said.

Putin has said Russia is not seeking war with Europe, but is ready for war if that is Europe's choice.


Pakistan Says ‘Hostile Countries’ behind False Online Claims Linking it to Australia Shootings

A man waves Pakistan's flag as he along with others gather in support of Pakistan Army, day after the ceasefire announcement between India and Pakistan, in Islamabad, Pakistan, May 11, 2025. REUTERS/Akhtar Soomro
A man waves Pakistan's flag as he along with others gather in support of Pakistan Army, day after the ceasefire announcement between India and Pakistan, in Islamabad, Pakistan, May 11, 2025. REUTERS/Akhtar Soomro
TT

Pakistan Says ‘Hostile Countries’ behind False Online Claims Linking it to Australia Shootings

A man waves Pakistan's flag as he along with others gather in support of Pakistan Army, day after the ceasefire announcement between India and Pakistan, in Islamabad, Pakistan, May 11, 2025. REUTERS/Akhtar Soomro
A man waves Pakistan's flag as he along with others gather in support of Pakistan Army, day after the ceasefire announcement between India and Pakistan, in Islamabad, Pakistan, May 11, 2025. REUTERS/Akhtar Soomro

Pakistan’s information minister said Wednesday that his country has been the victim of a coordinated online disinformation campaign following the mass shooting at Australia’s Bondi Beach.

Attaullah Tarar accused “hostile countries,” including India, of spreading false claims that one of the two attackers was a Pakistani national.

Speaking at a news conference in Islamabad, Tara said Pakistan's leadership strongly condemned Sunday's attack, which killed 15 people in an antisemitic shooting targeting Jews celebrating Hanukkah, The AP news reported.

The minister said misleading information began circulating almost immediately after the attack, with social media posts falsely identifying one of the suspects as a Pakistani national named Naveed Akram. He said the claims spread rapidly across digital platforms and were repeated by some media outlets without verification.

Tarar said subsequent findings, including confirmation by Indian police, established that one of the attackers, Sajid Akram, was from India, while his 24-year-old son, Naveed Akram — who was also involved — was born in Australia.

The minister said the misinformation appeared to stem from a case of mistaken identity, as a Pakistani man living in Sydney shares the same name as one of the two suspects.

“How do we restore the situation to where it was before the Bondi Beach attack?” Tarar asked, adding that the Pakistani man — also named Naveed Akram — had released a video denying any involvement and urging the public not to associate him with the attack.

Tara said the Pakistani man was “a victim of a malicious and organized campaign” and that the disinformation effort originated in India.

There was no immediate response from Indian officials.

Tarar called on media outlets that published the false reports to issue apologies and said Pakistan had not yet decided whether to pursue legal action.

Pakistan and India, nuclear-armed rivals, have a long history of strained relations and have fought three wars since gaining independence from British rule in 1947, most of them over the disputed Himalayan region of Kashmir. The two sides came close to war in May before US President Donald Trump brokered a ceasefire.