Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



Back From Iran, Pakistani Students Say They Heard Gunshots While Confined to Campus

 A Pakistani medical student Arslan Haider waits at the airport after arriving from Tehran on a commercial flight amid the ongoing nationwide protests in Iran, in Islamabad, Pakistan, January 15, 2026. (Reuters)
A Pakistani medical student Arslan Haider waits at the airport after arriving from Tehran on a commercial flight amid the ongoing nationwide protests in Iran, in Islamabad, Pakistan, January 15, 2026. (Reuters)
TT

Back From Iran, Pakistani Students Say They Heard Gunshots While Confined to Campus

 A Pakistani medical student Arslan Haider waits at the airport after arriving from Tehran on a commercial flight amid the ongoing nationwide protests in Iran, in Islamabad, Pakistan, January 15, 2026. (Reuters)
A Pakistani medical student Arslan Haider waits at the airport after arriving from Tehran on a commercial flight amid the ongoing nationwide protests in Iran, in Islamabad, Pakistan, January 15, 2026. (Reuters)

Pakistani students returning from Iran on Thursday said they heard gunshots and stories of rioting and violence while being confined to campus and not allowed out of their dormitories in the evening.

Iran's leadership is trying to quell the worst domestic unrest since its 1979 revolution, with a rights group putting the death toll over 2,600.

As the protests swell, Tehran is seeking to deter US President Donald Trump's repeated threats to intervene on behalf of anti-government protesters.

"During ‌nighttime, we would ‌sit inside and we would hear gunshots," Shahanshah ‌Abbas, ⁠a fourth-year ‌student at Isfahan University of Medical Sciences, said at the Islamabad airport.

"The situation down there is that riots have been happening everywhere. People are dying. Force is being used."

Abbas said students at the university were not allowed to leave campus and told to stay in their dormitories after 4 p.m.

"There was nothing happening on campus," Abbas said, but in his interactions with Iranians, he ⁠heard stories of violence and chaos.

"The surrounding areas, like banks, mosques, they were damaged, set on fire ... ‌so things were really bad."

Trump has repeatedly ‍threatened to intervene in support of protesters ‍in Iran but adopted a wait-and-see posture on Thursday after protests appeared ‍to have abated. Information flows have been hampered by an internet blackout for a week.

"We were not allowed to go out of the university," said Arslan Haider, a student in his final year. "The riots would mostly start later in the day."

Haider said he was unable to contact his family due to the blackout but "now that they opened international calls, the students are ⁠getting back because their parents were concerned".

A Pakistani diplomat in Tehran said the embassy was getting calls from many of the 3,500 students in Iran to send messages to their families back home.

"Since they don't have internet connections to make WhatsApp and other social network calls, what they do is they contact the embassy from local phone numbers and tell us to inform their families."

Rimsha Akbar, who was in the middle of her final year exams at Isfahan, said international students were kept safe.

"Iranians would tell us if we are talking on Snapchat or if we were riding in a cab ... ‌that shelling had happened, tear gas had happened, and that a lot of people were killed."


Bomb Hoax Forces Turkish Airlines to Make Emergency Landing in Barcelona

A Turkish Airlines aircraft after landing at El Prat airport, in Barcelona, northeastern Spain, 15 January 2026, after Spanish security forces where alerted due to a bomb threat on board the aircraft. (EPA)
A Turkish Airlines aircraft after landing at El Prat airport, in Barcelona, northeastern Spain, 15 January 2026, after Spanish security forces where alerted due to a bomb threat on board the aircraft. (EPA)
TT

Bomb Hoax Forces Turkish Airlines to Make Emergency Landing in Barcelona

A Turkish Airlines aircraft after landing at El Prat airport, in Barcelona, northeastern Spain, 15 January 2026, after Spanish security forces where alerted due to a bomb threat on board the aircraft. (EPA)
A Turkish Airlines aircraft after landing at El Prat airport, in Barcelona, northeastern Spain, 15 January 2026, after Spanish security forces where alerted due to a bomb threat on board the aircraft. (EPA)

A false bomb threat delivered via an onboard mobile connection caused a Turkish Airlines flight from Istanbul to make an emergency landing at Barcelona's El Prat Airport on Thursday, Spanish police and the airline ‌said.

A Turkish ‌Airlines spokesperson ‌said ⁠earlier that ‌the plane had landed after crew detected that a passenger had created an in-flight internet hotspot which was named to include a bomb threat as the aircraft approached ⁠Barcelona.

Spain's Guardia Civil police force said ‌in a statement ‍that following a ‍thorough inspection of the aircraft ‍after its passengers had disembarked, the alert had been deactivated and no explosives had been found. Spanish airport operator AENA said El Prat was operating normally.

Police have launched ⁠an investigation to determine who was behind the hoax, the statement added.

Türkiye's flag carrier has faced previous incidents of hoax threats, usually made via written messages, that led to emergency landings over the years.


US Sanctions Iranian Officials Over Protest Crackdown

 Treasury Secretary Scott Bessent watches as President Donald Trump speaks to reporters on the South Lawn at the White House, Tuesday, Jan. 13, 2026, in Washington. (AP)
Treasury Secretary Scott Bessent watches as President Donald Trump speaks to reporters on the South Lawn at the White House, Tuesday, Jan. 13, 2026, in Washington. (AP)
TT

US Sanctions Iranian Officials Over Protest Crackdown

 Treasury Secretary Scott Bessent watches as President Donald Trump speaks to reporters on the South Lawn at the White House, Tuesday, Jan. 13, 2026, in Washington. (AP)
Treasury Secretary Scott Bessent watches as President Donald Trump speaks to reporters on the South Lawn at the White House, Tuesday, Jan. 13, 2026, in Washington. (AP)

The United States imposed sanctions Thursday on Iranian security officials and financial networks, accusing them of orchestrating a violent crackdown on peaceful protests and laundering billions in oil revenues.

Treasury Secretary Scott Bessent announced the measures in the wake of the biggest anti-government protests in the history of the republic, although the demonstrations appear to have diminished over the last few days in the face of repression and an almost week-long internet blackout.

"The United States stands firmly behind the Iranian people in their call for freedom and justice," Bessent said in a statement, adding that the action was taken at President Donald Trump's direction.

Among those sanctioned is Ali Larijani, secretary of Iran's Supreme Council for National Security, whom Washington accused of coordinating the crackdown and calling for force against protesters.

Four regional commanders of Iran's Law Enforcement Forces and Revolutionary Guard were also sanctioned for their roles in the crackdown in Lorestan and Fars provinces.

Security forces in Fars "have killed countless peaceful demonstrators" with hospitals "so inundated with gunshot wound patients that no other types of patients can be admitted," the Treasury said.

The Treasury additionally designated 18 individuals and entities accused of operating "shadow banking" networks that launder proceeds from Iranian oil sales through front companies in the UAE, Singapore and Britain.

These networks funnel billions of dollars annually using cover companies and exchange houses, as Iranian citizens face economic hardship, according to the Treasury.

The sanctions freeze any US assets of those designated and prohibit Americans from doing business with them. Foreign financial institutions risk secondary sanctions for transactions with the designated entities.

The action builds on the Trump administration's "maximum pressure" campaign against Iran. In 2025, the Treasury sanctioned more than 875 persons, vessels and aircraft as part of this effort, it said.