The Microsoft SharePoint breach was massive. The response has been minimal

It’s not every day that U.S. nuclear facilities, the Department for Education, and governments across Europe and the Middle East are breached in a single hack. But then again, the vulnerability identified in Microsoft’s document collaboration tool, SharePoint, this weekend isn’t your ordinary issue. It has found a chink in the armor of one of the most widely used suites of software across the world. Microsoft holds a two-thirds market share in the business productivity space.

Microsoft disclosed the vulnerability in a blog post over the weekend, clarifying that the issue only affected on-premises SharePoint servers. These are locally hosted instances of the collaboration tool, rather than the more broadly used SharePoint Online system in Microsoft 365. The company rolled out updates to plug the hole in security, which it said customers “should apply […] immediately to ensure they are protected.”

Dozens of large organizations are known to have already been affected, including U.S. and international governments, and were hacked through the vulnerability. The breach has left some wondering why the reaction has been so muted, given the high-profile targets.

Darren Guccione, CEO and co-founder of Keeper Security, notes that although Microsoft 365’s cloud-based services are unaffected, many critical sectors—including government, legal, and financial institutions—still depend on older or hybrid SharePoint setups. These systems, he says, often “lack the visibility, access control and agility” needed to respond quickly with security updates.

Some cybersecurity experts say the response so far hasn’t reflected the seriousness of the threat. Alan Woodward, a cybersecurity professor at the University of Surrey, points out that the issue impacts on-premise installations rather than Microsoft-hosted ones. As a result, he explains, Microsoft’s role is limited to releasing a fix, leaving the rest up to organizations themselves. The company, he says, has essentially told users: “Over to you if you operate and maintain your own servers’ instance of SharePoint.” (Microsoft did not immediately respond to Fast Company‘s request to comment.)

Those servers are often held offline because they are used to store sensitive data, including in the delivery of government services, which isn’t trusted to be stored in cloud environments. “The awkward part of the story is that there are still several hundred thousand share points on premises,” Woodward says. “It could be a double-whammy if it’s not handled properly.”

Woodward says he’s been struck by the lack of urgency in the broader IT community’s response—including from Microsoft itself. Given the severity of the vulnerability, he expected the company to be far more vocal in alerting its technical user base. Microsoft, he says, should have been “shouting about it.” Meanwhile, both the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and U.K. National Cyber Security Center (NCSC) have issued warnings about the risks of the vulnerability.

Other experts are more sympathetic to Microsoft’s situation. “I have some sympathy for all parties here,” says Craig Clark, director of Clark & Company Information Services, a cybersecurity advisor. “Threats are evolving at such a rate that it’s almost impossible to keep up.”

Clark does admit that “Microsoft needs to be more dynamic in how it issues its advisories and remember that many security teams are small and perhaps more needs to be done to keep people better informed,” he says. But the relationship goes both ways. “For their part, security teams need the resources to ensure that patching is seen as more than just a nice to have,” he says.

One of Clark’s key concerns is how quickly attackers are now able to weaponize newly discovered vulnerabilities—something he attributes to rapid advancements in technology, particularly AI. He warns that threat actors are increasingly leveraging these tools to accelerate attacks, which will likely make incidents like this more frequent. Microsoft has already confirmed that Chinese state-sponsored hackers have exploited the flaw.

Fixing the problem long-term will be more complex, experts say. Clark advises layering security measures, isolating critical systems, and automating patching wherever possible. Ultimately, he says, organizations “need to move away from the patch when we can.” Still, what works in theory often falls short in practice—which is why such vulnerabilities continue to surface.

https://www.fastcompany.com/91373183/microsoft-sharepoint-breach-response-minimal?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Létrehozva 9h | 2025. júl. 23. 14:30:06


Jelentkezéshez jelentkezzen be

EGYÉB POSTS Ebben a csoportban

Tokenization is gaining ground in the crypto world. Here’s what to know

Tokenization has long been a buzzword for crypto enthusiasts, who have been arguing for years that blo

2025. júl. 23. 21:30:05 | Fast company - tech
‘Door kick challenge’ goes viral—but cops say the TikTok trend could lead to serious injury

Ding dong ditching has resurfaced as the “door kick challenge.” But this time it could lead to criminal charges and potentially deadly consequences. 

In Florida this week, five mino

2025. júl. 23. 21:30:04 | Fast company - tech
Alphabet’s Q2 revenue beats estimates as cloud computing surges

Alphabet beat Wall Street estimates for its second quarter on Wednesday, and cited massive

2025. júl. 23. 21:30:03 | Fast company - tech
‘So sorry, I grabbed your salad’: Women are reportedly stealing Sweetgreen salads to meet men

It’s been said that online dating killed the meet cute. Now, as people struggle with dating app burnout, some are supposedly resorting to stealing men’s lunches for a chance at creating their own.

2025. júl. 23. 16:50:04 | Fast company - tech
Coffee by the bucket is the summer’s wildest caffeine trend

A Trenta Starbucks is no longer cutting it. The latest coffee trend has people ordering their iced lattes by the bucket. 

Earlier this year, independent coffee shops started going viral

2025. júl. 23. 14:30:06 | Fast company - tech