CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA and international security agencies warn of a surge in ransomware attacks targeting Microsoft SharePoint and critical infrastructure.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a flaw within Microsoft SharePoint is currently being exploited in ransomware attacks. Concurrent reports indicate that a group known as the Gunra ransomware gang is specifically targeting critical infrastructure. This group is utilizing various vulnerabilities to breach networks, including flaws associated with Schneider Electric and Fortinet products, to facilitate their ransomware deployments. Coverage of these threats is being driven by a mix of government agencies and cybersecurity news outlets. BleepingComputer reported the specific CISA warning regarding Microsoft SharePoint, while The Hacker News detailed the Gunra ransomware gang's use of Fortinet and Schneider Electric flaws.
The Record from Recorded Future News highlighted the collaborative warnings issued by the FBI and South Korea regarding the targeting of critical infrastructure. Additionally, a LinkedIn alert noted that zero-day vulnerabilities in SonicWall SMA1000 are being exploited to breach enterprise networks. This series of events underscores a coordinated effort by security organizations to defend against sophisticated actors. The National Security Agency (NSA) joined the FBI and other partners in releasing formal guidance designed to help organizations defend against Gunra ransomware. The involvement of both the NSA and FBI, alongside international cooperation from South Korea, indicates the high stakes involved when critical infrastructure is targeted by ransomware gangs.
These attacks often rely on exploiting known or zero-day flaws in enterprise hardware and software to gain initial access. Future developments to monitor include the release of further defense guidance from the NSA and FBI as they continue to track the Gunra ransomware gang. Organizations using Microsoft SharePoint, Fortinet, Schneider Electric, and SonicWall SMA1000 systems are the primary focus of current security warnings. Coverage does not yet specify if patches for all mentioned flaws have been deployed, but the emphasis remains on the active exploitation of these specific vulnerabilities to breach enterprise and critical infrastructure networks.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (93% supported) Updated 2h ago.
Quick answers
Which software flaw did CISA warn is being used in ransomware attacks?
CISA warned that a flaw in Microsoft SharePoint is now being exploited in ransomware attacks.
Which agencies released guidance to defend against Gunra ransomware?
The NSA joined the FBI and other partners in releasing guidance to defend against Gunra ransomware.
What other hardware flaws are being exploited by the Gunra gang?
The Gunra ransomware gang is exploiting flaws in Fortinet and Schneider Electric to breach networks.
Coverage (6)
- Gunra ransomware expands globally as US, South Korean agencies warn of data theft, encryption and extortion tactics Industrial Cyber · 7h ago
- NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware National Security Agency (NSA) (.gov) · 7h ago
- WARNING: SonicWall SMA1000 Zero-Days Exploited To Breach Enterprise Networks LinkedIn · 7h ago
- FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The Record from Recorded Future News · 7h ago
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Hacker News · 7h ago
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks BleepingComputer · 7h ago
Topics
Related trends
FBI, NCAA Launch Effort to Protect College Athletes From Online Sexual Exploitation
The FBI and NCAA have launched a strategic partnership to protect college student-athletes from online sexual exploitation and sextortion crimes.
Kash Patel Gets a Warning From Moscow About His Russia Visit
Kash Patel's planned October visit to Russia is met with a stern warning from Moscow regarding the terms of his arrival.
Hugging Face hack marks start of dangerous AI cyber era and many firms 'don't even know it'
A consequential breach at Hugging Face has sparked warnings from former NSA officials about a dangerous new era of AI-accelerated cyber operations.
Daniel Cormier recounts calling alleged fixed UFC fight: ‘How in the world is this kid so bad’
Daniel Cormier recounts realizing an alleged fixed UFC fight during his live broadcast, leading to an FBI investigation.
EXCLUSIVE: Under Patel, FBI forges unprecedented law enforcement ties with China, Russia
4 news sources are covering this World story right now — PULSE is tracking how fast it spreads.
North Korea says US-led cyber threat warnings are bid to smear its image
6 news sources are covering this World story right now — PULSE is tracking how fast it spreads.