Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
10 results for “SharePoint”
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Attackers are actively exploiting a critical Microsoft SharePoint authentication bypass vulnerability (CVE-2026-55040, CVSS 9.1) after public release of PoC code, despite Microsoft having patched it in July 2026 Patch Tuesday.
Aug 13, 2026
Hackers leverage new Microsoft SharePoint exploit in attacks
Hackers are actively exploiting a newly disclosed critical Microsoft SharePoint vulnerability using a publicly released proof-of-concept exploit, posing immediate risk to organizations relying on SharePoint.
Aug 13, 2026
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers disclosed a critical unauthenticated remote code execution vulnerability (CVE-2026-55040, CVSS 9.1) in multiple Microsoft SharePoint Server versions, with AI assistance playing a significant role in its discovery.
Aug 11, 2026
Swiss government SharePoint breach compromised 200 accounts
Switzerland's federal IT office confirmed a cybersecurity breach of its Microsoft SharePoint servers, resulting in approximately 200 compromised accounts.
Aug 7, 2026
Microsoft 365 outage affects Teams, SharePoint and other services
A widespread Microsoft 365 outage disrupted core collaboration services including Teams, SharePoint, Excel, and the Admin Center, impacting enterprise and individual users globally.
Jul 23, 2026
Critical SharePoint RCE flaw exploited to steal machine keys
A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited to extract machine keys, enabling persistent post-patch access — representing an immediate, high-severity threat to enterprise infrastructure.
Jul 22, 2026
CISA warns admins to patch actively exploited SharePoint flaws
CISA issued an emergency advisory warning that three SharePoint Server vulnerabilities are under active exploitation, requiring immediate patching to prevent compromise of internet-exposed on-premises deployments.
Jul 15, 2026
New Helix vishing group emerges in SharePoint data theft attacks
A newly identified threat actor named Helix is conducting targeted data theft operations against SharePoint environments using identity-based attack vectors including vishing, device code phishing, and MFA bypass techniques.
Jul 10, 2026
Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list - The Register
CISA added a SharePoint remote code execution (RCE) vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, contradicting Microsoft's prior public assessment that exploitation was 'less likely'.
Published Jul 2, 2026 · Analyzed Jul 5, 2026
CISA: Microsoft SharePoint RCE flaw now actively exploited
CISA issued an advisory confirming active exploitation of a patched Microsoft SharePoint remote code execution vulnerability, signaling urgent risk to organizations still unpatched.
Published Jul 2, 2026 · Analyzed Jul 7, 2026