Microsoft (NASDAQ: MSFT) has issued an urgent security alert warning of active zero-day attacks targeting SharePoint servers used by government agencies and enterprises. The tech giant emphasized that the cloud-based SharePoint Online in Microsoft 365 remains unaffected. However, on-premise SharePoint servers, particularly SharePoint Subscription Edition, are at immediate risk due to a critical spoofing vulnerability.
The FBI confirmed awareness of the ongoing attacks and is coordinating with federal and private-sector partners, though it has not disclosed further details. According to The Washington Post, unidentified threat actors recently exploited this flaw to breach multiple U.S. and international organizations. Experts categorize this as a zero-day attack—a type of exploit targeting unknown software vulnerabilities—placing tens of thousands of servers at risk.
Microsoft explained the flaw allows an authorized attacker to conduct spoofing over a network, impersonating trusted sources to manipulate systems or gain unauthorized access. The company has released a security update for SharePoint Subscription Edition and strongly urges users to apply it immediately.
Security patches for SharePoint 2016 and 2019 are in development. Until they are available, Microsoft advises organizations unable to implement recommended malware protections to disconnect vulnerable servers from the internet to prevent potential breaches.
This incident highlights the growing threat to enterprise infrastructure and the importance of timely patch management. Organizations relying on SharePoint for internal collaboration should act swiftly to mitigate the risk. Cybersecurity experts recommend continuously monitoring systems, applying updates promptly, and maintaining layered defenses against evolving threats.
With active exploitation underway, the urgency for patching affected SharePoint servers cannot be overstated. Taking immediate steps can prevent data breaches and safeguard sensitive internal communications.


UPS MD-11 Crash Prompts Families to Prepare Wrongful Death Lawsuit
Firelight Launches as First XRP Staking Platform on Flare, Introduces DeFi Cover Feature
Taiwan Opposition Criticizes Plan to Block Chinese App Rednote Over Security Concerns
Senate Sets December 8 Vote on Trump’s NASA Nominee Jared Isaacman
Microchip Technology Boosts Q3 Outlook on Strong Bookings Momentum
Tesla Expands Affordable Model 3 Lineup in Europe to Boost EV Demand
Hikvision Challenges FCC Rule Tightening Restrictions on Chinese Telecom Equipment
Banks Consider $38 Billion Funding Boost for Oracle, Vantage, and OpenAI Expansion
Netflix Nearing Major Deal to Acquire Warner Bros Discovery Assets
YouTube Agrees to Follow Australia’s New Under-16 Social Media Ban
USPS Expands Electric Vehicle Fleet as Nationwide Transition Accelerates
Intel Boosts Malaysia Operations with Additional RM860 Million Investment
Anthropic Reportedly Taps Wilson Sonsini as It Prepares for a Potential 2026 IPO
EU Prepares Antitrust Probe Into Meta’s AI Integration on WhatsApp
Trump Administration to Secure Equity Stake in Pat Gelsinger’s XLight Startup
Wikipedia Pushes for AI Licensing Deals as Jimmy Wales Calls for Fair Compensation 



