Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



North Korea’s Kim Marks Completion of Pyongyang Housing Project as Key Party Congress Nears 

This picture taken on February 16, 2026 and released by North Korea's official Korean Central News Agency (KCNA) on February 17, 2026 shows North Korean leader Kim Jong Un (C) and his daughter Ju Ae (center L) attending the inauguration ceremony of 10,000 flats of the fourth stage in Hwasong Area of Pyongyang. (KCNA via KNS / AFP)
This picture taken on February 16, 2026 and released by North Korea's official Korean Central News Agency (KCNA) on February 17, 2026 shows North Korean leader Kim Jong Un (C) and his daughter Ju Ae (center L) attending the inauguration ceremony of 10,000 flats of the fourth stage in Hwasong Area of Pyongyang. (KCNA via KNS / AFP)
TT

North Korea’s Kim Marks Completion of Pyongyang Housing Project as Key Party Congress Nears 

This picture taken on February 16, 2026 and released by North Korea's official Korean Central News Agency (KCNA) on February 17, 2026 shows North Korean leader Kim Jong Un (C) and his daughter Ju Ae (center L) attending the inauguration ceremony of 10,000 flats of the fourth stage in Hwasong Area of Pyongyang. (KCNA via KNS / AFP)
This picture taken on February 16, 2026 and released by North Korea's official Korean Central News Agency (KCNA) on February 17, 2026 shows North Korean leader Kim Jong Un (C) and his daughter Ju Ae (center L) attending the inauguration ceremony of 10,000 flats of the fourth stage in Hwasong Area of Pyongyang. (KCNA via KNS / AFP)

North Korean leader Kim Jong Un marked the completion of 10,000 new houses built in Pyongyang, state media KCNA said on Tuesday, as the country prepares to hold a key party congress.

Kim has been touring construction sites and touting project progress ahead of this month's Ninth Congress of the ruling Workers' Party, the country's biggest political gathering that reviews performance, sets ‌new policy ‌goals and can bring leadership change.

On Monday, ‌Kim ⁠oversaw the completion ⁠ceremony for 10,000 houses in Hwasong District, Pyongyang, which achieved the goal of 50,000 new houses in the metropolitan area set during the Eighth Congress five years ago, according to state broadcaster KCNA.

This picture taken on February 16, 2026 and released by North Korea's official Korean Central News Agency (KCNA) on February 17, 2026 shows North Korean leader Kim Jong Un (center R) and his daughter Ju Ae (center L) attending the inauguration ceremony of 10,000 flats of the fourth stage in Hwasong Area of Pyongyang. (KCNA via KNS / AFP)

"Based on the transformational achievements... during the Eighth period, the Ninth Congress ⁠of the party will set a grander ‌goal of restoration and ‌creation," Kim said, according to KCNA.

Kim's daughter Ju Ae was ‌shown at her father's side at the completion ceremony, ‌hugging and congratulating the residents of the new estate. There has been increasing speculation among analysts and from South Korea's spy agency that Kim is grooming the teenager to ‌succeed him.

As part of their tour of the housing project, North Korean state TV ⁠showed Kim ⁠and Ju Ae also visiting an arcade game center that looked similar to an internet cafe, a musical instrument shop and an animal hospital where they petted a puppy.

Meanwhile, KCNA said those participating in the upcoming party congress arrived in Pyongyang on Monday.

In the past two instances in 2016 and 2021, the Congress began three to four days after representatives arrived in Pyongyang, according to Hong Min, an analyst at the Korea Institute for National Unification in Seoul.


At Least 14 Killed in Spate of Attacks in Northwest Pakistan

A spate of attacks in northwest Pakistan on Monday killed at least three civilians and 11 security personnel. Karim ULLAH / AFP
A spate of attacks in northwest Pakistan on Monday killed at least three civilians and 11 security personnel. Karim ULLAH / AFP
TT

At Least 14 Killed in Spate of Attacks in Northwest Pakistan

A spate of attacks in northwest Pakistan on Monday killed at least three civilians and 11 security personnel. Karim ULLAH / AFP
A spate of attacks in northwest Pakistan on Monday killed at least three civilians and 11 security personnel. Karim ULLAH / AFP

Two bomb attacks and a gunfight between police and militants in northwest Pakistan killed at least 11 security personnel and three civilians, including a child, a security official said.

The separate incidents on Monday in Khyber Pakhtunkhwa province, which left at least 25 others wounded, come as Pakistan's security forces battle intensifying insurgencies in southern and northern provinces that border Afghanistan.

This month the ISIS group claimed responsibility for a massive suicide blast at a mosque in the capital Islamabad that killed at least 31 people, with 169 more wounded.

Speaking on condition of anonymity, the security official told AFP that on Monday evening a suicide bomber rammed an explosives-laden vehicle into the wall of a religious college in the tribal district of Bajaur in Khyber Pakhtunkhwa.

"As a result, eight police and Frontier Corps personnel present inside the seminary were martyred and 10 others injured," he said.

"The blast also caused the roofs of several nearby houses to collapse, killing a child."

He added the death told may rise.

In another attack in the town of Bannu, a bomb planted in a rickshaw exploded at the Miryan police station, killing two civilians and wounding 17 others, the official said.

- Chinese targeted -

Elsewhere, three police personnel and three militants were also killed during a search operation in Shangla district.

The Khyber Pakhtunkhwa police force said in a statement, also late on Monday, that the three militants who died in the firefight had been involved in "attacks targeting Chinese nationals".

Beijing has poured billions of dollars into Pakistan in recent years, but Chinese-funded projects have sparked resentment and their citizens have frequently come under attack.

In March last year, five Chinese nationals working on a major dam construction site were killed along with their driver when a suicide bomber targeted their vehicle, which plunged into a deep ravine off the mountainous Karakoram Highway.

Beijing is Islamabad's closest regional ally, readily providing financial assistance to bail out its often struggling neighbor.

The China-Pakistan Economic Corridor (CPEC) has seen tens of billions of dollars funneled into massive transport, energy and infrastructure projects -- part of Beijing's transnational "Belt and Road" scheme.

The police statement said "due to the area's proximity to the Silk Road route, (the militants) posed a persistent threat to the strategic road corridor and Chinese development projects."

"In light of this, the Counter Terrorism Department (CTD) and the district police launched a joint operation today under a coordinated strategy."


India Seizes Three Iran-linked US-sanctioned Tankers

This photo posted on the X account of the US Department of Defense on February 15, 2026 shows what the Department of Defense says are US military forces preparing to interdict and board an oil tanker, the Veronica III, in the Indian Ocean. (Photo by Handout / US Department of Defense / AFP)
This photo posted on the X account of the US Department of Defense on February 15, 2026 shows what the Department of Defense says are US military forces preparing to interdict and board an oil tanker, the Veronica III, in the Indian Ocean. (Photo by Handout / US Department of Defense / AFP)
TT

India Seizes Three Iran-linked US-sanctioned Tankers

This photo posted on the X account of the US Department of Defense on February 15, 2026 shows what the Department of Defense says are US military forces preparing to interdict and board an oil tanker, the Veronica III, in the Indian Ocean. (Photo by Handout / US Department of Defense / AFP)
This photo posted on the X account of the US Department of Defense on February 15, 2026 shows what the Department of Defense says are US military forces preparing to interdict and board an oil tanker, the Veronica III, in the Indian Ocean. (Photo by Handout / US Department of Defense / AFP)

India has seized three US-sanctioned oil tankers linked to Iran this month and stepped up surveillance in its maritime zone to curb illicit trade, a source said on Monday, confirming a post on X by Indian authorities earlier in February that had been deleted.

India aims to prevent its waters from being used for ship-to-ship transfers that obscure the origin of oil cargoes, the source with direct knowledge of the matter told ‌Reuters.

The seizures and ‌heightened surveillance follow an improvement in US-India relations. Washington ‌earlier ⁠this month announced it ⁠will cut import tariffs on Indian goods to 18% from 50%, after New Delhi agreed to stop Russian oil imports.

The three sanctioned vessels - Stellar Ruby, Asphalt Star and Al Jafzia - frequently changed their identities to evade law enforcement by coastal states, the source said, adding that their owners were based overseas.

VESSELS SEIZED OFFSHORE MUMBAI

Iranian state media cited the National Iranian Oil Company as ⁠saying that the three tankers seized by India ‌had no connection to the company. It ‌said that neither the cargoes nor the vessels were linked to the company.

Indian authorities ‌had said in a post on X on February 6 that ‌they intercepted three vessels about 100 nautical miles west of Mumbai after detecting suspicious activity involving a tanker in India's exclusive economic zone.

The post was later deleted, but the source confirmed that the vessels had been escorted to Mumbai for ‌further investigation.

The Indian Coast Guard has since deployed about 55 ships and between 10 and 12 aircraft for round-the-clock ⁠surveillance in its ⁠maritime zones, according to the source.

The US Office of Foreign Assets Control said last year it had sanctioned three vessels, called Global Peace, Chil 1, and Glory Star 1, with IMO numbers identical to the ships lately captured by India.

Two of the three tankers are linked to Iran, with Al Jafzia having carried fuel oil from Iran to Djibouti in 2025 and Stellar Ruby flagged in Iran, according to LSEG data.

The Asphalt Star mostly operated on voyages around China, the data show.

Sanctioned oil and fuel are often sold at deep discounts due to the risks involved, with intermediaries moving cargo through complex ownership structures, false documentation and mid-sea transfers that complicate enforcement.