Tag: Microsoft SharePoint

US nuclear weapons agency hacked in Microsoft SharePoint attacks
News

US nuclear weapons agency hacked in Microsoft SharePoint attacks

By taking advantage of a newly fixed Microsoft SharePoint zero-day vulnerability chain, unknown threat actors have gained access to the National Nuclear Security Administration's network. As part of the Energy Department, NNSA is a semi-autonomous U.S. government agency responsible for maintaining the nation's nuclear weapons stockpile and responding to nuclear and radiological emergencies both domestically and internationally. Last week, hackers obtained access to NNSA networks, according to a statement from a Department of Energy official. Ben Dietderich, the press secretary for the Department of Energy, told BleepingComputer that the NNSA was among the agencies affected by the exploitation of a Microsoft SharePoint zero-day vulnerability read more about US nuclear weapons agen...
Gamma AI Platform Abused in Phishing Chain to Spoof Microsoft SharePoint Logins
News

Gamma AI Platform Abused in Phishing Chain to Spoof Microsoft SharePoint Logins

Gamma, a presentation platform driven by artificial intelligence (AI), is being used by threat actors in phishing attacks to trick unwary users into visiting fake Microsoft login sites. In an investigation published Tuesday, researchers Hinman Baron and Piotr Wojtyla of Abnormal Security claimed that attackers use Gamma, a relatively new AI-based presentation tool, as a weapon to provide a link to a phony Microsoft SharePoint login process. A phishing email, sometimes sent from authentic, compromised email accounts, is the first step in the attack chain. Its purpose is to trick recipients into opening an embedded PDF document. When the victim clicks on the links in the PDF attachment, they are taken to a presentation hosted on Gamma, where they are prompted read more about Gamma ...
Microsoft SharePoint Connector Flaw Could’ve Enabled Credential Theft Across Power Platform
News

Microsoft SharePoint Connector Flaw Could’ve Enabled Credential Theft Across Power Platform

The Microsoft SharePoint connector on Power Platform has a fixed vulnerability that, if successfully exploited, might enable threat actors to gather user credentials and launch follow-on attacks, according to cybersecurity researchers. In a study sent to The Hacker News before to publication, Zenity Labs stated that this could take the shape of post-exploitation steps that permit the attacker to submit queries to the SharePoint API on behalf of the fictitious user, granting unauthorized access to private information. The potential impact is greatly increased by the fact that this vulnerability may be used to exploit Power Automate, Power Apps, Copilot Studio, and Copilot 365, according to senior security researcher Dmitry Lozovoy read more about Microsoft SharePoint Connector Flaw C...
CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability
News

CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability

Based on proof of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security hole affecting Microsoft Sharepoint Server to its list of known exploited vulnerabilities (KEV). This significant remote code execution vulnerability, identified as CVE-2023-24955 (CVSS score: 7.2), enables arbitrary code execution by an authorized attacker with Site Owner capabilities. An authorized attacker might remotely execute code on the SharePoint Server as a Site Owner through a network-based attack, according to a warning from Microsoft. Microsoft fixed the vulnerability in its May 2023 Patch Tuesday patches. The update was made more than two months after CISA included CVE-2023-29357, a SharePoint Server privilege escalation vulnerabili...