Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



UK Police Charge Two Men with Belonging to Hezbollah, Attending Terrorism Training

Hezbollah flags flutter as protesters, mainly Houthi supporters, rally to show support to Palestinians in the Gaza Strip and Lebanon's Hezbollah, in Sanaa, Yemen September 27, 2024. (Reuters)
Hezbollah flags flutter as protesters, mainly Houthi supporters, rally to show support to Palestinians in the Gaza Strip and Lebanon's Hezbollah, in Sanaa, Yemen September 27, 2024. (Reuters)
TT

UK Police Charge Two Men with Belonging to Hezbollah, Attending Terrorism Training

Hezbollah flags flutter as protesters, mainly Houthi supporters, rally to show support to Palestinians in the Gaza Strip and Lebanon's Hezbollah, in Sanaa, Yemen September 27, 2024. (Reuters)
Hezbollah flags flutter as protesters, mainly Houthi supporters, rally to show support to Palestinians in the Gaza Strip and Lebanon's Hezbollah, in Sanaa, Yemen September 27, 2024. (Reuters)

Two British-Lebanese men appeared in a London court on Tuesday, charged with belonging to the banned Iran-backed group Hezbollah and attending terrorism training camps, with one of the two accused of helping procure parts for drones.

Annis Makki, 40, is charged with attending a terrorist training camp at the Birket Jabbour airbase in Lebanon in 2021, being involved in the preparation of terrorist acts, being a member of Hezbollah, and expressing support both for Hezbollah and the banned Palestinian group Hamas.

Mohamed Hadi Kassir, 33, is also accused of belonging to Hezbollah and attending a training camp in Baffliyeh in south Lebanon in 2015 and at the Birket Jabbour airbase in 2021. He indicated not guilty pleas to the charges.

Prosecutor Kristel Pous told Westminster Magistrates' Court that Kassir was "an entrenched member of Hezbollah" and that images had been found of him "training in a Hezbollah-controlled camp and undertaking hostage training exercises in 2015".

Pous also said Makki had access to a "wide-ranging Hezbollah network" which was linked to facilitating the acquisition of parts to be used in unmanned aerial vehicles.

Judge Paul Goldspring remanded both men in custody until their next court appearance at London's Old Bailey court on January 16.

The men were arrested at their home addresses in London in April and rearrested last week when they were subsequently charged.

Commander Dominic Murphy, head of London's Counter Terrorism Policing, said in a statement before Tuesday's hearing: "I want to reassure the public that I do not assess there is an ongoing threat to the wider public as a result of the activities of these two individuals."


Millions Facing Acute Food Insecurity in Afghanistan as Winter Looms, UN Warns

Boys stay on a hilltop overlooking Kabul, Afghanistan, Feb. 27, 2022. (AP)
Boys stay on a hilltop overlooking Kabul, Afghanistan, Feb. 27, 2022. (AP)
TT

Millions Facing Acute Food Insecurity in Afghanistan as Winter Looms, UN Warns

Boys stay on a hilltop overlooking Kabul, Afghanistan, Feb. 27, 2022. (AP)
Boys stay on a hilltop overlooking Kabul, Afghanistan, Feb. 27, 2022. (AP)

More than 17 million people in Afghanistan are facing crisis levels of hunger in the coming winter months, the leading international authority on hunger crises and the UN food aid agency warned Tuesday.

The number at risk is some 3 million more than a year ago.

Economic woes, recurrent drought, shrinking international aid and influx of Afghans returning home from countries like neighboring Iran and Pakistan have strained resources and added to the pressures on food security, reports the Integrated Food Security Phase Classification, known as IPC, which tracks hunger crises.

"What the IPC tells us is that more than 17 million people in Afghanistan are facing acute food insecurity. That is 3 million more than last year," said Jean-Martin Bauer, director of food security at the UN's World Food Program, told reporters in Geneva.

"There are almost 4 million children in a situation of acute malnutrition," he said by video from Rome. "About 1 million are severely acutely malnourished, and those are children who actually require hospital treatment."

Food assistance in Afghanistan is reaching only 2.7% of the population, the IPC report says — exacerbated by a weak economy, high unemployment and lower inflows of remittances from abroad — as more than 2.5 million people returned from Iran and Pakistan this year.

More than 17 million people, or more than one-third of the population, are set to face crisis levels of food insecurity in the four-month period through to March 2026, the report said. Of those, 4.7 million could face emergency levels of food insecurity.

An improvement is expected by the spring harvest season starting in April, IPC projected.

The UN last week warned of a "severe" and "precarious" crisis in the country as Afghanistan enters its first winter in years without US foreign assistance and almost no international food distribution.

Tom Fletcher, the UN humanitarian chief, told the Security Council on Wednesday that the situation has been exacerbated by "overlapping shocks," including recent deadly earthquakes, and the growing restrictions on humanitarian aid access and staff.

While Fletcher said nearly 22 million Afghans will need UN assistance in 2026, his organization will focus on 3.9 million facing the most urgent need of lifesaving help in light of the reduced donor contributions.


Suspected Militants Kill 2, Including a Police Officer Guarding Polio Team in Northwestern Pakistan

A health worker marks a child’s finger after administering a polio vaccination in Hyderabad, Pakistan, 15 December 2025. EPA/NADEEM KHAWAR
A health worker marks a child’s finger after administering a polio vaccination in Hyderabad, Pakistan, 15 December 2025. EPA/NADEEM KHAWAR
TT

Suspected Militants Kill 2, Including a Police Officer Guarding Polio Team in Northwestern Pakistan

A health worker marks a child’s finger after administering a polio vaccination in Hyderabad, Pakistan, 15 December 2025. EPA/NADEEM KHAWAR
A health worker marks a child’s finger after administering a polio vaccination in Hyderabad, Pakistan, 15 December 2025. EPA/NADEEM KHAWAR

Suspected militants opened fire on a police officer guarding a team of polio workers in northwestern Pakistan on Tuesday, killing the officer and a passerby before fleeing, police said.
No polio worker was harmed in the attack that occurred in Bajaur, a district of Khyber Pakhtunkhwa province bordering Afghanistan, according to local police chief Samad Khan, The Associated Press said.
No group immediately claimed responsibility for the attack, but suspicion is likely to fall on the Pakistani Taliban and other militant groups blamed by the government for similar attacks in the region and elsewhere in the country.
The shooting came a day after Pakistan launched a weeklong nationwide vaccination campaign aimed at immunizing 45 million children. According to the World Health Organization, Pakistan and Afghanistan remain the only two countries where polio has not been eradicated.
Prime Minister Shehbaz Sharif condemned the attack in a statement and vowed strong action against those responsible.
Pakistan has reported 30 polio cases since January, down from 74 during the same period last year, according to a statement from the government-run Polio Eradication Initiative.
Pakistan regularly launches campaigns against polio despite attacks on the workers and police assigned to the inoculation drives. Militants falsely claim the vaccination campaigns are a Western conspiracy to sterilize children.
More than 200 polio workers and police assigned to protect them have been killed in Pakistan since the 1990s, according to health and security officials.