SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
ID: a8565b2c-f462-5f04-b51e-b14897a14833
STIX ID: report--a8565b2c-f462-5f04-b51e-b14897a14833
Feed Name: Security Affairs
Swiss Federal IT Agency FOITT disclosed that unknown attackers exploited recently disclosed Microsoft SharePoint vulnerabilities (including CVE-2026-50522, CVSS 9.8) to compromise about 200 user and technical accounts on on-premises SharePoint servers; FOITT blocked external access, began patching, reset credentials, and is reinstalling affected servers as investigations with NCSC and Microsoft continue. The report warns that theft of machine keys allows forging of legitimate requests and persistent access, recommends applying July patches, rotating machine keys and restarting IIS, and cautions against directly exposing SharePoint servers to the internet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
