Close Menu
Stratnews GlobalStratnews Global
    Facebook X (Twitter) Instagram
    Trending
    • SpaceX IPO Could Top $1 Trillion as Investors Rush In
    • Time Names AI Architects as 2025 Person of the Year
    • NAACP Issues Framework to Prevent Bias in Healthcare AI
    • Cambridge Study Finds Fake Accounts Can Be Created for Just Cents
    • Caribbean Nations Unite to Harness Geothermal Energy Potential
    • U.S. Pushes to End Reliance on Chinese Lidar Technology
    • Trump Moves to Block Broadband Funds Over State AI Regulations
    Stratnews GlobalStratnews Global
    Write for Us
    Sunday, December 14
    • Space
    • Science
    • AI and Robotics
    • Industry News
    Stratnews GlobalStratnews Global
    Home » Massive Cyber Espionage Hits Microsoft Servers: 100 Organisations Breached Globally

    Massive Cyber Espionage Hits Microsoft Servers: 100 Organisations Breached Globally

    Aditya LenkaBy Aditya LenkaJuly 22, 2025 General No Comments3 Mins Read

    A sweeping cyber-espionage campaign exploiting a critical vulnerability in Microsoft’s server software has compromised at least 100 organisations worldwide, according to cybersecurity researchers who exposed the operation.

    Over the weekend, Microsoft issued an urgent alert warning of “active attacks” targeting self-hosted SharePoint servers, software commonly used by firms for internal document sharing and collaboration. Microsoft-hosted SharePoint services remain unaffected.

    The cyber assault, dubbed a “zero-day” attack due to its reliance on a previously undiscovered software flaw, allows hackers to infiltrate servers and potentially implant backdoors for ongoing access to compromised networks.

    Vaisha Bernard, chief hacker at Netherlands-based cybersecurity firm Eye Security, revealed that nearly 100 victims had been identified through a global scan using Shadowserver Foundation tools. These findings came before the method of exploitation became widely known, suggesting more breaches may now exist.

    “It’s unambiguous,” Bernard said. “Who knows what other adversaries have done since to place other backdoors.” He refrained from naming affected organisations, citing official security protocols and notification of national authorities.

    The Shadowserver Foundation corroborated Bernard’s count, noting that most compromised servers were located in the United States and Germany, with victims including government agencies.

    Rafe Pilling, Director of Threat Intelligence at UK-based Sophos, added that the attack, for now, appears to be the work of a single entity or coordinated group, but warned this could change rapidly as awareness of the flaw spreads.

    Microsoft confirmed that security updates had been released and urged all users to apply them promptly.

    The identity of the hackers remains uncertain. However, Alphabet-owned Google, leveraging its expansive visibility across internet traffic, attributed some of the breaches to a China-linked threat actor. As expected, China’s government has denied involvement.

    The FBI acknowledged awareness of the attacks and stated it was working alongside both public and private partners, without divulging further details. Britain’s National Cyber Security Centre also noted a “limited number” of targets in the UK.

    Analysts warn that the scale of potential exposure is massive. Shodan, a search engine that maps internet-connected devices, estimates that over 8,000 servers globally could be vulnerable. Shadowserver places the figure slightly higher, above 9,000.

    High-profile potential targets include major industrial firms, financial institutions, auditors, healthcare providers, and government bodies across both U.S. state and international jurisdictions.

    Daniel Card of British cybersecurity consultancy PwnDefend cautioned, “The SharePoint incident appears to have created a broad level of compromise across a range of servers globally. Assuming breach is wise—and applying the patch alone isn’t enough.”

    Cybersecurity experts advise organisations to investigate server logs for signs of compromise and to undertake comprehensive incident response beyond mere patching to ensure security.

    With inputs from Reuters

    Author

    • Aditya Lenka
      Aditya Lenka

      A multi-faceted professional with a diverse range of skills and experiences. He currently works as a Producer, Digital Marketer, and Journalist for several well-known media outlets, namely StratNewsGlobal, BharatShakti, and Interstellar. With a passion for storytelling and a keen eye for detail, Aditya has covered a wide range of topics and events across India, bringing a unique perspective to his work.When he's not busy producing content, Aditya enjoys exploring new places and cuisines, having traveled extensively throughout India. He's also an avid writer and poet, often penning his thoughts and musings in his free time. And when he wants to unwind and relax, Aditya spends time with his two loyal companions, Zorro and Pablo, his beloved dogs.Aditya's dynamic personality and varied interests make him a unique individual, always eager to learn and experience new things.

      View all posts
    cyber-espionage campaign Featured google Just In Organisations PwnDefend Shadowserver technology
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Reddit Telegram WhatsApp
    Aditya Lenka
    Aditya Lenka

      A multi-faceted professional with a diverse range of skills and experiences. He currently works as a Producer, Digital Marketer, and Journalist for several well-known media outlets, namely StratNewsGlobal, BharatShakti, and Interstellar. With a passion for storytelling and a keen eye for detail, Aditya has covered a wide range of topics and events across India, bringing a unique perspective to his work.When he's not busy producing content, Aditya enjoys exploring new places and cuisines, having traveled extensively throughout India. He's also an avid writer and poet, often penning his thoughts and musings in his free time. And when he wants to unwind and relax, Aditya spends time with his two loyal companions, Zorro and Pablo, his beloved dogs.Aditya's dynamic personality and varied interests make him a unique individual, always eager to learn and experience new things.

      Keep Reading

      SpaceX IPO Could Top $1 Trillion as Investors Rush In

      Time Names AI Architects as 2025 Person of the Year

      NAACP Issues Framework to Prevent Bias in Healthcare AI

      Cambridge Study Finds Fake Accounts Can Be Created for Just Cents

      Caribbean Nations Unite to Harness Geothermal Energy Potential

      U.S. Pushes to End Reliance on Chinese Lidar Technology

      Add A Comment
      Leave A Reply Cancel Reply

      Anti Drone System (CUAS)
      Latest Posts

      SpaceX IPO Could Top $1 Trillion as Investors Rush In

      December 12, 2025

      Time Names AI Architects as 2025 Person of the Year

      December 12, 2025

      NAACP Issues Framework to Prevent Bias in Healthcare AI

      December 12, 2025

      Cambridge Study Finds Fake Accounts Can Be Created for Just Cents

      December 12, 2025

      Caribbean Nations Unite to Harness Geothermal Energy Potential

      December 12, 2025

      U.S. Pushes to End Reliance on Chinese Lidar Technology

      December 12, 2025

      Trump Moves to Block Broadband Funds Over State AI Regulations

      December 12, 2025

      December 11, 2025

      Financial Inclusion Revisited: Counting Lives Changed

      December 11, 2025

      DAE Reports Record Nuclear Power Generation and Scientific Milestones in 2025

      December 11, 2025

      Subscribe to News

      Get the latest sports news from NewsSite about world, sports and politics.

      • Astronomical Events
      • Space Missions
      • Industry News
      • Science
      StratNewsGlobal Tech
      Facebook X (Twitter) Instagram LinkedIn YouTube
      © 2025 StratNews Global, A unit of BharatShakti Communications LLP
      • About Us
      • Contributors
      • Copyright
      • Contact
      • Write for Us

      Type above and press Enter to search. Press Esc to cancel.