Microsoft confirmed a live ransomware campaign targeting on-prem SharePoint servers (2016, 2019, Subscription Edition). Multiple CVEs are being actively exploited. We broke down the attack chain, immediate response steps, and how organizations can secure systems now.
This is affecting public and private sector orgs — including the U.S. National Nuclear Security Administration.
Our team at Zelda Security is helping orgs investigate, patch, and recover.
Curious if anyone here has spotted unusual SharePoint activity in your environments?
This is affecting public and private sector orgs — including the U.S. National Nuclear Security Administration.
Our team at Zelda Security is helping orgs investigate, patch, and recover.
Curious if anyone here has spotted unusual SharePoint activity in your environments?