Thursday , September 17 2026
SharePoint

Swiss gov.t SharePoint incident compromised 200 accounts

Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The Federal Office for Information Technology and Telecommunication (BIT) found the cyberattack after security experts saw strange activity on its SharePoint servers on July 28.

After confirming the incident, BIT stopped outside internet access to SharePoint, fixed the suspected issues, and changed the passwords for the affected accounts.

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

“During the analysis, security specialists discovered on Friday, July 31, that the login credentials for several accounts had been compromised,” BIT said.

The agency thinks the attackers used SharePoint weaknesses that Microsoft revealed in mid-July and fixed in the July Patch Tuesday updates. But, it hasn’t said which issue was exploited.

The attack might have used CVE-2026-56164, a SharePoint weakness that lets users gain higher access, or CVE-2026-50522, a serious flaw that lets attackers run their code remotely and steal keys to SharePoint machines even after fixes were made.

Both flaws were fixed in the July 2026 Patch Tuesday updates. It is still unknown if either weakness was used in the Swiss government attack or if the attackers took advantage of another issue that was fixed in those updates. BIT is looking into the incident with help from the Swiss Federal Office for Cyber Security and Microsoft.

So far, it has found no evidence that data was stolen beyond the compromised login credentials.

The agency said secret info and very personal data can’t be kept on the affected SharePoint site. BIT is putting the damaged servers back in place as a safety measure, and outside access will stay closed until this is done.

Federal workers can still access and share documents with outside people using other ways. Currently, no ransomware or data theft group has said they caused the problem.

Related Topic:

Ransomware group leaked 65,000 Swiss government documents

OWASP Unveils GenAI LLM Top 10 2026 For Modern AI APPS

Check Also

5

TP-Link alerts users to patch router auth bypass vulnerability

TP-Link fixed some security flaws in its Archer NX routers. CVE-2025-15517 is a security flaw …