Wednesday , August 26 2026
SharePoint

Swiss gov.t SharePoint incident compromised 200 accounts

Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The Federal Office for Information Technology and Telecommunication (BIT) found the cyberattack after security experts saw strange activity on its SharePoint servers on July 28.

After confirming the incident, BIT stopped outside internet access to SharePoint, fixed the suspected issues, and changed the passwords for the affected accounts.

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

“During the analysis, security specialists discovered on Friday, July 31, that the login credentials for several accounts had been compromised,” BIT said.

The agency thinks the attackers used SharePoint weaknesses that Microsoft revealed in mid-July and fixed in the July Patch Tuesday updates. But, it hasn’t said which issue was exploited.

The attack might have used CVE-2026-56164, a SharePoint weakness that lets users gain higher access, or CVE-2026-50522, a serious flaw that lets attackers run their code remotely and steal keys to SharePoint machines even after fixes were made.

Both flaws were fixed in the July 2026 Patch Tuesday updates. It is still unknown if either weakness was used in the Swiss government attack or if the attackers took advantage of another issue that was fixed in those updates. BIT is looking into the incident with help from the Swiss Federal Office for Cyber Security and Microsoft.

So far, it has found no evidence that data was stolen beyond the compromised login credentials.

The agency said secret info and very personal data can’t be kept on the affected SharePoint site. BIT is putting the damaged servers back in place as a safety measure, and outside access will stay closed until this is done.

Federal workers can still access and share documents with outside people using other ways. Currently, no ransomware or data theft group has said they caused the problem.

Related Topic:

Ransomware group leaked 65,000 Swiss government documents

OWASP Unveils GenAI LLM Top 10 2026 For Modern AI APPS

Check Also

5

TP-Link alerts users to patch router auth bypass vulnerability

TP-Link fixed some security flaws in its Archer NX routers. CVE-2025-15517 is a security flaw …