Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



France Accuses Iran of ‘Repression’ in Sentence for Nobel Laureate

People cross an intersection in downtown Tehran, Iran, Monday, Feb. 9, 2026. (AP)
People cross an intersection in downtown Tehran, Iran, Monday, Feb. 9, 2026. (AP)
TT

France Accuses Iran of ‘Repression’ in Sentence for Nobel Laureate

People cross an intersection in downtown Tehran, Iran, Monday, Feb. 9, 2026. (AP)
People cross an intersection in downtown Tehran, Iran, Monday, Feb. 9, 2026. (AP)

France accused Iran on Monday of "repression and intimidation" after a court handed Nobel Peace Prize laureate Narges Mohammadi a new six-year prison sentence on charges of harming national security.

Mohammadi, sentenced Saturday, was also handed a one-and-a-half-year prison sentence for "propaganda" against Iran's system, according to her foundation.

"With this sentence, the Iranian regime has, once again, chosen repression and intimidation," the French foreign ministry said in a statement, describing the 53-year-old as a "tireless defender" of human rights.

Paris is calling for the release of the activist, who was arrested before protests erupted nationwide in December after speaking out against the government at a funeral ceremony.

The movement peaked in January as authorities launched a crackdown that activists say has left thousands dead.

Over the past quarter-century, Mohammadi has been repeatedly tried and jailed for her vocal campaigning against Iran's use of capital punishment and the mandatory dress code for women.

Mohammadi has spent much of the past decade behind bars and has not seen her twin children, who live in Paris, since 2015.

Iranian authorities have arrested more than 50,000 people as part of their crackdown on protests, according to US-based Human Rights Activists News Agency (HRANA).


Iran's Supreme Leader Urges Iranians to Show 'Resolve' against Foreign Pressure

Iran's supreme leader Ali Khamenei on (File Photo/Supreme Leader's website).
Iran's supreme leader Ali Khamenei on (File Photo/Supreme Leader's website).
TT

Iran's Supreme Leader Urges Iranians to Show 'Resolve' against Foreign Pressure

Iran's supreme leader Ali Khamenei on (File Photo/Supreme Leader's website).
Iran's supreme leader Ali Khamenei on (File Photo/Supreme Leader's website).

Iran's supreme leader Ali Khamenei on Monday called on his compatriots to show "resolve" ahead of the anniversary of the 1979 Islamic revolution this week.

Since the revolution, "foreign powers have always sought to restore the previous situation", Ali Khamenei said, referring to the period when Iran was under the rule of shah Reza Pahlavi and dependent on the United States, AFP reported.

"National power is less about missiles and aircraft and more about the will and steadfastness of the people," the leader said, adding: "Show it again and frustrate the enemy."


UK PM's Communications Director Quits

British Prime Minister Keir Starmer delivers a speech at Horntye Park Sports Complex in St Leonards, Britain, February 05, 2026. Peter Nicholls/Pool via REUTERS
British Prime Minister Keir Starmer delivers a speech at Horntye Park Sports Complex in St Leonards, Britain, February 05, 2026. Peter Nicholls/Pool via REUTERS
TT

UK PM's Communications Director Quits

British Prime Minister Keir Starmer delivers a speech at Horntye Park Sports Complex in St Leonards, Britain, February 05, 2026. Peter Nicholls/Pool via REUTERS
British Prime Minister Keir Starmer delivers a speech at Horntye Park Sports Complex in St Leonards, Britain, February 05, 2026. Peter Nicholls/Pool via REUTERS

British Prime Minister Keir Starmer's director of communications Tim Allan resigned on Monday, a day after Starmer's top aide Morgan McSweeney quit over his role in backing Peter Mandelson over his known links to Jeffrey Epstein.

The loss of two senior aides ⁠in quick succession comes as Starmer tries to draw a line under the crisis in his government resulting from his appointment of Mandelson as ambassador to the ⁠US.

"I have decided to stand down to allow a new No10 team to be built. I wish the PM and his team every success," Allan said in a statement on Monday.

Allan served as an adviser to Tony Blair from ⁠1992 to 1998 and went on to found and lead one of the country’s foremost public affairs consultancies in 2001. In September 2025, he was appointed executive director of communications at Downing Street.