Updated
Updated · The Register · Aug 11
North Korean Hackers Exploit SharePoint Zero-Day After Microsoft Patch Fails
Updated
Updated · The Register · Aug 11

North Korean Hackers Exploit SharePoint Zero-Day After Microsoft Patch Fails

2 articles · Updated · The Register · Aug 11

Summary

  • North Korean actors are exploiting an unpatched zero-day in on-premises Microsoft SharePoint, extending active attacks against self-hosted servers.
  • Microsoft’s fixes failed to fully close the vulnerability, leaving on-prem deployments exposed even after patching attempts.
  • The flaw follows broader exploitation of SharePoint bug CVE-2026-45659, which CISA said ransomware gangs had abused since early July.
  • More than 8,500 SharePoint servers are exposed online, underscoring the scale of risk for organizations still running vulnerable on-prem systems.

Insights

Why is Microsoft hesitating to label this SharePoint flaw as actively exploited while CISA confirms ransomware attacks?
With SharePoint 2019 officially unsupported, are organizations unknowingly leaving their front doors wide open to ransomware?
If attackers already stole your SharePoint machine keys, does patching this critical flaw actually lock them out?