Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



EU to Slash Asylum Cases from 7 Nations Deemed Safe

FILE - A convoy of buses carry Syrian refugees who return home from Lebanon, arrive at the Syrian border crossing point, in Jdeidet Yabous, Syria, Tuesday, July 29, 2025. (AP Photo/Omar Sanadiki, File)
FILE - A convoy of buses carry Syrian refugees who return home from Lebanon, arrive at the Syrian border crossing point, in Jdeidet Yabous, Syria, Tuesday, July 29, 2025. (AP Photo/Omar Sanadiki, File)
TT

EU to Slash Asylum Cases from 7 Nations Deemed Safe

FILE - A convoy of buses carry Syrian refugees who return home from Lebanon, arrive at the Syrian border crossing point, in Jdeidet Yabous, Syria, Tuesday, July 29, 2025. (AP Photo/Omar Sanadiki, File)
FILE - A convoy of buses carry Syrian refugees who return home from Lebanon, arrive at the Syrian border crossing point, in Jdeidet Yabous, Syria, Tuesday, July 29, 2025. (AP Photo/Omar Sanadiki, File)

The European Union on Thursday said it would drastically reduce asylum claims from seven nations in Africa, the Middle East and Asia by considering them safe countries of origin, prompting widespread outrage from human rights groups on International Migrants' Day.

An agreement between European Parliament and the European Council, or the group of the 27 EU heads of state, said that the countries would be considered safe if they lack “relevant circumstances, such as indiscriminate violence in the context of an armed conflict.”

Asylum requests by people from Bangladesh, Colombia, Egypt, Kosovo, India, Morocco and Tunisia will be "fast-tracked, with applicants having to prove that this provision should not apply to them,” read the announcement of the agreement. “The list can be expanded in the future under the EU’s ordinary legislative procedure.”

In 2024, EU nations endorsed sweeping reforms to the bloc’s failed asylum system. The rules were meant to resolve the issues that have divided the 27 countries since well over 1 million migrants swept into Europe in 2015, most fleeing war in Syria and Iraq.

Under the Pact on Migration and Asylum, which goes into force in June 2026, people can be sent to countries deemed safe, but not to those where they face the risk of physical harm or persecution.

According to The Associated Press, Amnesty International EU advocate Olivia Sundberg Diez said the new measures were “a shameless attempt to sidestep international legal obligations" and would endanger migrants.

French MEP Mélissa Camara said the safe countries of origins concept and others agreed to by the Council and Parliament “opens the door to return hubs outside the EU’s borders, where third-country nationals are sometimes subjected to inhumane treatment with almost no monitoring” and “undoubtedly places thousands of people in exile in situations of danger.”

Céline Mias, the EU director of the Danish Refugee Council said that "we are deeply worried that this fast-track system will fail to protect people in need of protection, including activists, journalists and marginalized groups in places where human rights are clearly under attack.”

Alessandro Ciriani, an Italian MEP with the European Conservatives and Reformists group, said the designation sends a firm message that the EU has toughened its borders.

“Europe wants enforceable rules and shared responsibility. Now this commitment must become operational: effective returns, structured cooperation with third countries and real measures to support EU member states,” he said.

He said that clear delineations of safe and unsafe nations would rid the EU of “excessive interpretative uncertainty” that led to a kind of paralysis for national decision makers over border controls.

The measures also allows individual nations within the bloc to designate other countries safe for their own immigration purposes.


Rubio Says US Sanctioning ICC Judges for Targeting Israel

US Secretary of State Marco Rubio speaks to traveling journalists at the John C. Munro Hamilton International Airport in Hamilton, Ontario, on November 12, 2025 after the G7 foreign ministers meeting. (Photo by Mandel NGAN / POOL / AFP)
US Secretary of State Marco Rubio speaks to traveling journalists at the John C. Munro Hamilton International Airport in Hamilton, Ontario, on November 12, 2025 after the G7 foreign ministers meeting. (Photo by Mandel NGAN / POOL / AFP)
TT

Rubio Says US Sanctioning ICC Judges for Targeting Israel

US Secretary of State Marco Rubio speaks to traveling journalists at the John C. Munro Hamilton International Airport in Hamilton, Ontario, on November 12, 2025 after the G7 foreign ministers meeting. (Photo by Mandel NGAN / POOL / AFP)
US Secretary of State Marco Rubio speaks to traveling journalists at the John C. Munro Hamilton International Airport in Hamilton, Ontario, on November 12, 2025 after the G7 foreign ministers meeting. (Photo by Mandel NGAN / POOL / AFP)

US Secretary of State Marco Rubio said on Thursday that the US was sanctioning two judges of the International Criminal Court for targeting Israel.

"Today, I am designating two International Criminal Court (ICC) judges, Gocha Lordkipanidze of Georgia and Erdenebalsuren Damdin of Mongolia, pursuant to Executive Order 14203," Rubio said in a statement, referring to the order President Donald Trump signed in February sanctioning the ICC, Reuters reported.

"These individuals have directly engaged in efforts by the ICC to investigate, arrest, detain, or prosecute Israeli nationals, without Israel's consent," he said.

The United States and Israel are not members of the ICC.

The US sanctions in February include freezing any US assets of those designated and barring them and their families from visiting the United States.


US Imposes Sanctions on Vessels Linked to Iran, Treasury Website Says

A crew member raises the Iranian flag on Iranian oil tanker Adrian Darya 1, previously named Grace 1, as it sits anchored after the Supreme Court of the British territory lifted its detention order, in the Strait of Gibraltar, Spain, August 18, 2019. REUTERS/Jon Nazca
A crew member raises the Iranian flag on Iranian oil tanker Adrian Darya 1, previously named Grace 1, as it sits anchored after the Supreme Court of the British territory lifted its detention order, in the Strait of Gibraltar, Spain, August 18, 2019. REUTERS/Jon Nazca
TT

US Imposes Sanctions on Vessels Linked to Iran, Treasury Website Says

A crew member raises the Iranian flag on Iranian oil tanker Adrian Darya 1, previously named Grace 1, as it sits anchored after the Supreme Court of the British territory lifted its detention order, in the Strait of Gibraltar, Spain, August 18, 2019. REUTERS/Jon Nazca
A crew member raises the Iranian flag on Iranian oil tanker Adrian Darya 1, previously named Grace 1, as it sits anchored after the Supreme Court of the British territory lifted its detention order, in the Strait of Gibraltar, Spain, August 18, 2019. REUTERS/Jon Nazca

The United States imposed sanctions on Thursday on 29 vessels and their management firms, the Treasury Department said, as Washington continues targeting Tehran's "shadow fleet" it says exports Iranian petroleum and petroleum products, Reuters reported.

The targeted vessels and companies have transported hundreds of millions of dollars of the products through deceptive shipping practices, Treasury said.

Thursday's action also targets businessman Hatem Elsaid Farid Ibrahim Sakr, whose companies are associated with seven of the vessels cited, as well as multiple shipping companies.