Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The Federal Office for Information Technology and Telecommunication (BIT) found the cyberattack after security experts saw strange activity on its SharePoint servers on July 28.
After confirming the incident, BIT stopped outside internet access to SharePoint, fixed the suspected issues, and changed the passwords for the affected accounts.
By infosecbulletin
/ Friday , August 7 2026
Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The...
Read More
By infosecbulletin
/ Friday , August 7 2026
The ISACA Dhaka Chapter Election for 2026–2028 will take place on 8, August-2026. Most of the executive roles are likely...
Read More
By infosecbulletin
/ Thursday , August 6 2026
Cisco has put out an important update for Cisco IOS XE Software. This update fixes serious security holes that could...
Read More
By infosecbulletin
/ Thursday , August 6 2026
The Open Web Application Security Project (OWASP) has published the Top 10 for LLM Applications 2026. This guide focuses on...
Read More
By infosecbulletin
/ Wednesday , August 5 2026
Greatness has emerged as a phishing-as-a-service platform designed to steal Microsoft 365 access at a time when many organizations assume...
Read More
By infosecbulletin
/ Wednesday , August 5 2026
Bangladesh's National Cyber Security Agency (NCSA) has launched two cybersecurity initiatives: the Cyber Incident Reporting System (CIRS) and the National...
Read More
By infosecbulletin
/ Wednesday , August 5 2026
Cybersecurity Researcher Jeremiah Fowler uncovered and reported to Express VPN a publicly exposed database that was neither password-protected nor encrypted....
Read More
By infosecbulletin
/ Tuesday , August 4 2026
Thousands of data centers are in danger because of a 22-year-old problem in Baseboard Management Controller (BMC) processors, says the...
Read More
By infosecbulletin
/ Tuesday , August 4 2026
In an important move to boost the country's cybersecurity, Bangladesh started the Cyber Incident Reporting System (CIRS) and the National...
Read More
By infosecbulletin
/ Tuesday , August 4 2026
Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
“During the analysis, security specialists discovered on Friday, July 31, that the login credentials for several accounts had been compromised,” BIT said.
The agency thinks the attackers used SharePoint weaknesses that Microsoft revealed in mid-July and fixed in the July Patch Tuesday updates. But, it hasn’t said which issue was exploited.
The attack might have used CVE-2026-56164, a SharePoint weakness that lets users gain higher access, or CVE-2026-50522, a serious flaw that lets attackers run their code remotely and steal keys to SharePoint machines even after fixes were made.
Both flaws were fixed in the July 2026 Patch Tuesday updates. It is still unknown if either weakness was used in the Swiss government attack or if the attackers took advantage of another issue that was fixed in those updates. BIT is looking into the incident with help from the Swiss Federal Office for Cyber Security and Microsoft.
So far, it has found no evidence that data was stolen beyond the compromised login credentials.
The agency said secret info and very personal data can’t be kept on the affected SharePoint site. BIT is putting the damaged servers back in place as a safety measure, and outside access will stay closed until this is done.
Federal workers can still access and share documents with outside people using other ways. Currently, no ransomware or data theft group has said they caused the problem.
Related Topic:
Ransomware group leaked 65,000 Swiss government documents
OWASP Unveils GenAI LLM Top 10 2026 For Modern AI APPS