Last updated:
Microsoft Sharepoint Hack Breaches: During the investigation, it was found that Microsoft’s Shaypoint software attack could not survive Marika’s National Nuclear Security Administration ie NNSA. Zero-Day weaknessRead more

Highlights
- Cyber detective campaign started due to zero-day weakness in sharepoint.
- More than 100 organizations were targeted, NNSA also affected.
- Microsoft issued additional updates, the danger is not yet averted.
Hackers stole Cryptographic Keys from Toolshell!
This weakness has been named ‘Toolshell’. Taking advantage of this, hackers stole cryptographic keys and webshals on sharepoint servers, which gave them almost complete control over the servers. Microsoft released a patch earlier this month, but cybercautic firms found it insufficient. Hackers have soon developed new ways to bypass this patch. It was said that it is possible to violate a large level. Microsoft has now released additional updates, but the danger is not yet averted.
The scope of the attack is shocking. From government agencies to financial institutions, healthcare providers and large corporations, no one remained untouched by this cyber storm. Cybercharity experts estimate that more than 8,000 sharepoint servers are still unsafe and active exploitation continues in many networks. The American Cybercharity and Infrastructure Security Agency (CISA) has warned organizations running on-dimisive sharepoint servers to immediately implement the latest patch and take additional security measures. CISA also said that only patching cannot be enough. This is because the stolen keys can give hackers the ability to infiltrate the system later.
Doubt of Chinese hackers
Microsoft and security experts have associated these attacks with Hacking groups ‘Linen Typhoon’ and ‘Violet Typhoon’ associated with China. Although Beijing has denied any involvement in cyber attacks, the incident highlights the threat of important infrastructure and sophisticated cyber espionage operations targeting government institutions. Organizations are now advised not only to apply the patch, but also to rotate the intensive examination of their system and rotate the cryptographic keys to prevent future attacks. This cyber attack is a rigorous reminder of security challenges in the digital age.

I am active in journalism for more than 14 years long. In 2010, after starting his career with Dainik Bhaskar newspaper, he worked as a reporter in New World, Dainik Jagran and Punjab Kesari. During this time crime and …Read more
I am active in journalism for more than 14 years long. In 2010, after starting his career with Dainik Bhaskar newspaper, he worked as a reporter in New World, Dainik Jagran and Punjab Kesari. During this time crime and … Read more