Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



UK PM's Top Aide Quits over Mandelson-Epstein Scandal

FILE PHOTO: British Prime Minister Keir Starmer talks with Britain's ambassador to the United States Peter Mandelson during a welcome reception at the ambassador's residence on February 26, 2025, in Washington, DC, US. Carl Court/Pool via REUTERS/File Photo
FILE PHOTO: British Prime Minister Keir Starmer talks with Britain's ambassador to the United States Peter Mandelson during a welcome reception at the ambassador's residence on February 26, 2025, in Washington, DC, US. Carl Court/Pool via REUTERS/File Photo
TT

UK PM's Top Aide Quits over Mandelson-Epstein Scandal

FILE PHOTO: British Prime Minister Keir Starmer talks with Britain's ambassador to the United States Peter Mandelson during a welcome reception at the ambassador's residence on February 26, 2025, in Washington, DC, US. Carl Court/Pool via REUTERS/File Photo
FILE PHOTO: British Prime Minister Keir Starmer talks with Britain's ambassador to the United States Peter Mandelson during a welcome reception at the ambassador's residence on February 26, 2025, in Washington, DC, US. Carl Court/Pool via REUTERS/File Photo

British Prime Minister Keir Starmer's chief of staff, Morgan McSweeney, quit on Sunday, saying he took responsibility for advising Starmer to name Peter Mandelson as ambassador to the US despite his known links to Jeffrey Epstein.

After new files revealed the depth of the Labour veteran's relationship with the late sex offender, Starmer is facing what is widely seen as the gravest crisis of his 18 months in power over his decision to send Mandelson to Washington in 2024, Reuters reported.

The loss of McSweeney, 48, a strategist who was instrumental in Starmer's rise to power, is the latest in a series of setbacks, less than two years after the Labour Party won one of the largest parliamentary majorities in modern British history.

With polls showing Starmer is hugely unpopular with voters after a series of embarrassing U-turns, some in his own party are openly questioning his judgment and his future, and it remains to be seen whether McSweeney's exit will be enough to silence critics.

The files released in the US on January 30 sparked a police investigation for misconduct in office over indications that Mandelson leaked market-sensitive information to Epstein when he was a government minister during the global financial crisis in 2009 and 2010.

In a statement, McSweeney said: "The decision to ⁠appoint Peter Mandelson was wrong. He has damaged our party, our country and trust in politics itself.
"When asked, I advised the Prime Minister to make that appointment and I take full responsibility for that advice."

The leader of the opposition Conservative Party, Kemi Badenoch, said the resignation was overdue and that "Keir Starmer has to take responsibility for his own terrible decisions".

Nigel Farage, head of the populist Reform UK party, which is leading in the polls, said he believed Starmer's time would soon be up.

Starmer has spent the last week defending McSweeney, a strategy that could prompt further questions about his own judgment. In a statement on Sunday, Starmer said it had been "an honor" working with him.

Many Labour members of parliament had blamed McSweeney for the appointment of Mandelson and the damage caused by the publication of the exchanges between Epstein ⁠and Mandelson. Others have said Starmer must go.

One Labour lawmaker, speaking on condition of anonymity, said McSweeney's resignation had come too late: "It buys the PM time, but it's still the end of days."

Starmer sacked Mandelson as ambassador in September over his links to Epstein.

The government agreed last week to release virtually all previously private communications between members of his government from the time when Mandelson was being appointed.

That release could come as early as this week, creating a new headache for Starmer just as he hopes to move on. If previously secret messages about how London planned to approach its relationship with Donald Trump are made public, it could damage Starmer's relationship with the US President.

McSweeney had held the role of chief of staff since October 2024, when he was handed the job following the resignation of Sue Gray after a row over pay and donations.

Starmer on Sunday appointed his deputy chiefs of staff, Jill Cuthbertson and Vidhya Alakeson, to serve as joint acting chiefs of staff.


Iran Sentences Nobel Laureate Narges Mohammadi to 7 More Years in Prison

(FILES) A handout photo provided by the Narges Mohammadi Foundation on October 2, 2023 shows an undated, unlocated photo of Iranian rights campaigner Narges Mohammadi. (Photo by Handout / NARGES MOHAMMADI FOUNDATION / AFP)
(FILES) A handout photo provided by the Narges Mohammadi Foundation on October 2, 2023 shows an undated, unlocated photo of Iranian rights campaigner Narges Mohammadi. (Photo by Handout / NARGES MOHAMMADI FOUNDATION / AFP)
TT

Iran Sentences Nobel Laureate Narges Mohammadi to 7 More Years in Prison

(FILES) A handout photo provided by the Narges Mohammadi Foundation on October 2, 2023 shows an undated, unlocated photo of Iranian rights campaigner Narges Mohammadi. (Photo by Handout / NARGES MOHAMMADI FOUNDATION / AFP)
(FILES) A handout photo provided by the Narges Mohammadi Foundation on October 2, 2023 shows an undated, unlocated photo of Iranian rights campaigner Narges Mohammadi. (Photo by Handout / NARGES MOHAMMADI FOUNDATION / AFP)

Iran sentenced Nobel Peace Prize laureate Narges Mohammadi to over seven more years in prison after she began a hunger strike, supporters said Sunday.

Mohammadi’s supporters cited her lawyer, who spoke to Mohammadi.

The lawyer, Mostafa Nili, confirmed the sentence on X, saying it had been handed down Saturday by a Revolutionary Court in the city of Mashhad. Such courts typically issue verdicts with little or no opportunity for defendants to contest their charges.

“She has been sentenced to six years in prison for ‘gathering and collusion’ and one and a half years for propaganda and two-year travel ban,” he wrote, according to The Associated Press.

She received another two years of internal exile to the city of Khosf, some 740 kilometers (460 miles) southeast of Tehran, the capital, the lawyer added.

Supporters say Mohammadi has been on a hunger strike since Feb. 2. She had been arrested in December at a ceremony honoring Khosrow Alikordi, a 46-year-old Iranian lawyer and human rights advocate who had been based in Mashhad. Footage from the demonstration showed her shouting, demanding justice for Alikordi and others.

Supporters had warned for months before her December arrest that Mohammadi, 53, was at risk of being put back into prison after she received a furlough in December 2024 over medical concerns.

While that was to be only three weeks, Mohammadi’s time out of prison lengthened, possibly as activists and Western powers pushed Iran to keep her free. She remained out even during the 12-day war in June between Iran and Israel.

Mohammadi still kept up her activism with public protests and international media appearances, including even demonstrating at one point in front of Tehran’s notorious Evin prison, where she had been held.

Mohammadi had been serving 13 years and nine months on charges of collusion against state security and propaganda against Iran’s government.

She also had backed the nationwide protests sparked by the 2022 death of Mahsa Amini, which have seen women openly defy the government by not wearing the hijab.

Mohammadi suffered multiple heart attacks while imprisoned before undergoing emergency surgery in 2022, her supporters say. Her lawyer in late 2024 revealed doctors had found a bone lesion that they feared could be cancerous that later was removed.

“Considering her illnesses, it is expected that she will be temporarily released on bail so that she can receive treatment,” Nili wrote.

However, Iranian officials have been signaling a harder line against all dissent since the recent demonstrations. Speaking on Sunday, Iranian judiciary chief Gholamhossein Mohseni-Ejei made comments suggesting harsh prison sentences awaited many.

“Look at some individuals who once were with the revolution and accompanied the revolution," he said. "Today, what they are saying, what they are writing, what statements they issue, they are unfortunate, they are forlorn (and) they will face damage.”


Nigeria's President to Make a Sate Visit to the UK in March

Nigeria’s President Bola Tinubu gives a joint statement with Brazil’s President Luiz Inacio Lula da Silva, at the Planalto presidential palace, in Brasilia, Brazil, Aug. 25, 2025. (AP Photo/Eraldo Peres, File)
Nigeria’s President Bola Tinubu gives a joint statement with Brazil’s President Luiz Inacio Lula da Silva, at the Planalto presidential palace, in Brasilia, Brazil, Aug. 25, 2025. (AP Photo/Eraldo Peres, File)
TT

Nigeria's President to Make a Sate Visit to the UK in March

Nigeria’s President Bola Tinubu gives a joint statement with Brazil’s President Luiz Inacio Lula da Silva, at the Planalto presidential palace, in Brasilia, Brazil, Aug. 25, 2025. (AP Photo/Eraldo Peres, File)
Nigeria’s President Bola Tinubu gives a joint statement with Brazil’s President Luiz Inacio Lula da Silva, at the Planalto presidential palace, in Brasilia, Brazil, Aug. 25, 2025. (AP Photo/Eraldo Peres, File)

Nigeria’s president is set to make a state visit to the UK in March, the first such trip by a Nigerian leader in almost four decades, Britain’s Buckingham Palace said Sunday.

Officials said President Bola Tinubu and first lady Oluremi Tinubu will travel to the UK on March 18 and 19, The AP news reported.

King Charles III and Queen Camilla will host them at Windsor Castle. Full details of the visit are expected at a later date.

Charles visited Nigeria, a Commonwealth country, four times from 1990 to 2018 before he became king. He previously received Tinubu at Buckingham Palace in September 2024.m

Previous state visits by a Nigerian leader took place in 1973, 1981 and 1989.

A state visit usually starts with an official reception hosted by the king and includes a carriage procession and a state banquet.

Last year Charles hosted state visits for world leaders including US President Donald Trump, French President Emmanuel Macron and German President Frank-Walter Steinmeier.