
A sweeping cyber-espionage campaign leveraging vulnerable versions of Microsoft SharePoint server software has now impacted approximately 400 organizations, according to researchers at Netherlands-based Eye Security.
This figure, derived from an analysis of digital artifacts discovered during scans of servers running susceptible versions of Microsoft’s SharePoint software, represents a substantial increase from the 100 organizations cataloged over the weekend. Eye Security asserts that the current count likely underestimates the true scale of the compromise.
“There are many more, because not all attack vectors have left artifacts that we could scan for,” stated Vaisha Bernard, Chief Hacker for Eye Security, which was among the first organizations to identify these breaches.
The identities of most victim organizations have not yet been fully disclosed. However, on Wednesday, a representative for the National Institutes of Health (NIH) confirmed that one of its servers had been compromised. “Additional servers were isolated as a precaution,” he added. The news of the NIH compromise was initially reported by the Washington Post.
The espionage campaign commenced after Microsoft failed to fully patch a security vulnerability in its SharePoint server software, triggering an urgent effort to remediate the flaw upon its discovery. Both Microsoft and its technology rival, Google owner Alphabet, have indicated that Chinese state-sponsored hackers are among the groups exploiting this vulnerability. Beijing has publicly denied these claims.