Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
TT

Global Hack on Microsoft Hits US State Agencies

The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 
The Microsoft logo seen at the Hannover Messe industrial trade fair on March 31, 2025, in Hanover, Germany (Reuters) 

Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching US federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers.

Microsoft on Saturday issued an alert about “active attacks” on self-hosted SharePoint servers, which are widely used by organizations to share documents and collaborate within organizations. SharePoint instances run off of Microsoft servers were unaffected.

The FBI said on Sunday it was aware of the attacks and was working closely with its federal and private-sector partners, but offered no other details.

The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft.

Last year, the company was faulted by a panel of US government and industry experts for lapses that enabled a 2023 targeted Chinese hack of US government emails, including those of then-Commerce Secretary Gina Raimondo.

This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said.

After first suggesting that users make modifications to or simply unplug SharePoint server programs from the internet, the company on Sunday evening released a patch for one version of the software.

Two other versions remain vulnerable and Microsoft said it is continuing to work to develop a patch.

Microsoft updated its guidance Sunday with instructions to fix the problem for SharePoint Server 2019 and SharePoint Server Subscription Edition. Engineers were still working on a fix for the older SharePoint Server 2016 software.

“Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.”

Pete Renals, a senior manager with Palo Alto Networks’ Unit 42 said, “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available. We have identified dozens of compromised organizations spanning both commercial and government sectors.’’

With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted, according to The Washington Post.

What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched.

“So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing.

It was not immediately clear who is behind the hacking of global reach or what its ultimate goal is.

One private research company found the hackers targeting servers in China as well as a state legislature in the eastern United States. Eye Security said it has tracked more than 50 breaches, including at an energy company in a large state and several European government agencies.

Others that were breached included a government agency in Spain, a local agency in Albuquerque and a university in Brazil, security researchers said.

One state official in the eastern US said the attackers had “hijacked” a repository of documents provided to the public to help residents understand how their government works. The agency involved can no longer access the material, but it wasn’t clear whether it was deleted.

Some security companies said they had not seen deletions in the SharePoint attacks, only the theft of cryptographic keys that would allow the hackers to reenter the servers.

CISA spokesperson Marci McCarthy said the agency was alerted to the issue Friday by a cyber research firm and immediately contacted Microsoft.

Microsoft has been faulted in the past for issuing fixes that are too narrowly designed and leave similar avenues open to attack.

 



Macron Urges 'Calm' ahead of Tense Rally for Slain Far-right Activist

French police secure the area after a bomb threat at the headquarters of France's hard-left party La France Insoumise (France Unbowed - LFI) and its evacuation in Paris, France, February 18, 2026. REUTERS/Sarah Meyssonnier
French police secure the area after a bomb threat at the headquarters of France's hard-left party La France Insoumise (France Unbowed - LFI) and its evacuation in Paris, France, February 18, 2026. REUTERS/Sarah Meyssonnier
TT

Macron Urges 'Calm' ahead of Tense Rally for Slain Far-right Activist

French police secure the area after a bomb threat at the headquarters of France's hard-left party La France Insoumise (France Unbowed - LFI) and its evacuation in Paris, France, February 18, 2026. REUTERS/Sarah Meyssonnier
French police secure the area after a bomb threat at the headquarters of France's hard-left party La France Insoumise (France Unbowed - LFI) and its evacuation in Paris, France, February 18, 2026. REUTERS/Sarah Meyssonnier

French President Emmanuel Macron appealed on Saturday for cooler heads to prevail ahead of a rally for a far-right activist whose killing, blamed on the hard left, has put the country on edge.

Macron also said his government would hold a meeting next week to discuss "violent action groups" in the wake of the fatal beating of Quentin Deranque, which has ignited tensions between the left and right ahead of the 2027 presidential vote.

The 23-year-old died from head injuries following clashes between radical left and far-right supporters on the sidelines of a demonstration against a politician from the left-wing France Unbowed (LFI) party in the southeastern city of Lyon last week.

A rally, widely publicized online by ultra-nationalist and far-right groups, is expected to be attended by 2,000 to 3,000 people, with the authorities fearing further clashes with left-wing protesters.

Speaking at a farming trade fair in Paris, Macron urged "everyone to remain" calm ahead of the rally for Deranque in Lyon, which is set to go ahead under high security later on Saturday despite Lyon's left-wing green mayor asking the state to ban it.

"In the Republic, no violence is legitimate," said Macron, who will be unable to contest next year's election after hitting the two-term limit. "There is no place for militias, no matter where they come from."

- 'Over 1,000 neo-Nazis' -

Ahead of the Lyon rally, some residents living near the march's planned route had barricaded the ground floor windows of their apartments, fearing unrest.

"At my age, I'm not going to play the tough guy. If I have to go out somewhere, I'll avoid the places where they're marching," said Lyon local Jean Echeverria, 87.

"They'll just keep fighting each other, it'll never end. Between the extreme of this and the extreme of that, it's non-stop," he added.

Two friends of Deranque's were behind the official call to march in his honor.

But according to the Deranque family's lawyer, Fabien Rajon, his parents will not take part in the rally, which they have urged to go ahead "without violence" and "without political statements".

Several ultra-right-wing groups, including Deranque's nationalist Allobroges Bourgoin faction, have nonetheless heavily publicized the march on social media.

The authorities fear that far-right and hard-left activists from elsewhere in Europe might travel to France for the event, stoking concerns of further unrest.

Jordan Bardella, the head of the anti-immigration National Rally (RN) party -- which senses its best chance ever of scoring the presidency in next year's vote -- has urged supporters not to go.

"We ask you, except in very specific and strictly supervised local situations not to attend these gatherings nor to associate the National Rally with them," he wrote in a message sent to party officials and seen by AFP.

LFI coordinator Manuel Bompard backed the Lyon mayor's call for a ban, warning on X that the march would be a "fascist demonstration" which "over 1,000 neo-Nazis from all over Europe" were expected to attend.

But Interior Minister Laurent Nunez declined to ban the rally, arguing that he had to "strike a balance between maintaining public order and freedom of expression" and pledging an "extremely large police deployment".

- 'Wound' -

Deranque's death has provoked a reaction from US President Donald Trump's administration, with state department official Sarah Rogers on Friday branding the killing "terrorism" and claiming that "violent radical leftism is on the rise".

Likewise, Italian Prime Minister Giorgia Meloni on Wednesday called Deranque's death "a wound for all Europe", prompting Macron to urge the far-right leader to stay out of French matters.

Six men suspected of involvement in the fatal assault have been charged over the killing, while a parliamentary assistant to a radical left-wing MP has also been charged with complicity.

A far-right collective called Nemesis, which claims to "defend Western women" from the violence allegedly wrought by immigrants, said Deranque had been at the protest in Lyon to protect its members when he was assaulted by "anti-fascist" activists.

Having urged both the far right and hard left to clean up their acts, Macron said his administration would hold a meeting next week "take stock of violent action groups which are active and have links with political parties of any description".


US Military Strikes Another Alleged Drug Boat in Eastern Pacific, Killing 3

A shot of a boat targeted by a US raid in the Caribbean (archive - Reuters)
A shot of a boat targeted by a US raid in the Caribbean (archive - Reuters)
TT

US Military Strikes Another Alleged Drug Boat in Eastern Pacific, Killing 3

A shot of a boat targeted by a US raid in the Caribbean (archive - Reuters)
A shot of a boat targeted by a US raid in the Caribbean (archive - Reuters)

The US military said Friday that it has carried out another deadly strike on a vessel accused of trafficking drugs in the Eastern Pacific Ocean.

US Southern Command said on social media that the boat “was transiting along known narco-trafficking routes in the Eastern Pacific and was engaged in narco-trafficking operations.” It said the strike killed three people. A video linked to the post shows a boat floating in the water before bursting into flames.

Friday’s attack raises the death toll from the Trump administration’s strikes on alleged drug boats to at least 148 people in at least 43 attacks carried out since early September in the Caribbean Sea and eastern Pacific Ocean.

President Donald Trump has said the US is in “armed conflict” with cartels in Latin America and has justified the attacks as a necessary escalation to stem the flow of drugs. But his administration has offered little evidence to support its claims of killing “narcoterrorists.”

Critics have questioned the overall legality of the strikes as well as their effectiveness, in part because the fentanyl behind many fatal overdoses is typically trafficked to the US over land from Mexico.


Afghanistan Quake Causes No ‘Serious’ Damage, Injuries, Says Official

Afghan men prepare meals during the holy fasting month of Ramadan in Kabul, Afghanistan, 19 February 2026. (EPA)
Afghan men prepare meals during the holy fasting month of Ramadan in Kabul, Afghanistan, 19 February 2026. (EPA)
TT

Afghanistan Quake Causes No ‘Serious’ Damage, Injuries, Says Official

Afghan men prepare meals during the holy fasting month of Ramadan in Kabul, Afghanistan, 19 February 2026. (EPA)
Afghan men prepare meals during the holy fasting month of Ramadan in Kabul, Afghanistan, 19 February 2026. (EPA)

A 5.8-magnitude earthquake that rocked eastern Afghanistan including the capital Kabul has resulted in only minor damage and one reported injury, a disaster official told AFP on Saturday.

The quake hit on Friday just as people in the Muslim-majority country were sitting down to break their Ramadan fast.

The epicenter was near several remote villages around 130 kilometers (80 miles) northeast of Kabul, the United States Geological Survey said.

"There aren't any serious casualties or damages after yesterday's earthquake," said Mohammad Yousuf Hamad, spokesman for the National Disaster Management Authority.

He added that one person had sustained "a minor injury in Takhar", in Afghanistan's north, "and three houses had minor damage in Laghman" province.

Zilgay Talabi, a resident of Khenj district near the epicenter, said the tremor was "very strong, it went on for almost 30 seconds".

Earthquakes are common in Afghanistan, particularly along the Hindu Kush mountain range, near where the Eurasian and Indian tectonic plates meet.

In August last year, a shallow 6.0-magnitude quake in the country's east wiped out mountainside villages and killed more than 2,200 people.

Weeks later, a 6.3-magnitude quake in northern Afghanistan killed 27 people.

Large tremors in western Herat, near the Iranian border, in 2023, and in Nangarhar province in 2022, killed hundreds and destroyed thousands of homes.

Many homes in the predominantly rural country, which has been devastated by decades of war, are shoddily built.

Poor communication networks and infrastructure in mountainous Afghanistan have hampered disaster responses in the past, preventing authorities from reaching far-flung villages for hours or even days before they could assess the extent of the damage.