Microsoft SharePoint Server 0-Day Exploit Hits African Treasury, Businesses, and University

A global cyberattack has exploited a critical 0-day vulnerability in Microsoft SharePoint Server, affecting approximately 400 entities worldwide, including significant organizations across Africa.

The breach, reportedly detected by Dutch cybersecurity firm Eye Security, has compromised government agencies, large corporations, and educational institutions, with notable incidents in the United States, Mauritius, Jordan, South Africa, and the Netherlands.

Experts warn the actual number of victims may be far higher, given the widespread adoption of on-premise SharePoint solutions.

The attack specifically targets on-premise SharePoint installations, rather than Microsoft-managed cloud environments.

Eye Security’s investigation unearthed that South Africa was among the regions most impacted, with identified victims including a prominent car manufacturer, a leading university, several local government bodies, and a federal government agency.

Security teams at multiple institutions are presently conducting forensic analyses, while technical details of the exploit remain under wraps pending further investigation.

Infrastructure Sites Breached

South Africa’s National Treasury has confirmed an incident involving malware discovered on its Infrastructure Reporting Model website.

While the Treasury reported no system-wide disruptions, it has initiated collaboration with Microsoft Corp. and is intensifying incident response procedures.

The infection, believed to be the result of the broader SharePoint vulnerability being exploited globally, poses a risk to confidential data and raises concerns about supply chain and government resiliency.

Eye Security, which has been sharing findings with South Africa’s Computer Security Incident Response Team (CSIRT), notes that two additional unnamed South African organizations have also suffered breaches tied to this campaign.

Vaisha Bernard, co-owner of Eye Security, emphasized the scale of the attack, refusing to publicly name affected entities but confirming the presence of compromised assets across both public and private sectors.

SharePoint On-Prem Hosting

Microsoft’s SharePoint platform is heavily relied upon in South Africa for secure document storage and collaboration, often as an on-premise solution to provide organizations with greater control and perceived security.

Ironically, this very architecture is what the attackers have leveraged, exploiting vulnerabilities only present in locally hosted SharePoint deployments.

Cloud-based SharePoint environments managed by Microsoft are reportedly unaffected by the current wave of attacks.

The nature of the exploit, a 0-day (previously unknown) vulnerability, means affected organizations could have been compromised without prior detection or available patches.

Cybersecurity specialists are warning institutions running on-premise SharePoint servers to review configuration integrity, apply all security updates, and closely monitor for anomalous activity linked to data exfiltration or lateral movement.

According to the report, Microsoft has yet to issue a public statement addressing inquiries about the specific vulnerabilities or offering detailed remediation steps.

Meanwhile, security organizations are coordinating with affected parties to contain the threat, implement mitigations, and share intelligence within the broader cybersecurity community.

This campaign underscores the growing risks faced by organizations maintaining legacy or on-premise software systems, particularly when patches may lag or critical vulnerabilities are not swiftly addressed.

In South Africa, where digital infrastructure is a foundation for government processes and business operations, the incident serves as a stark reminder of the need to prioritize proactive patch management, vulnerability scanning, and layered security defenses.

Security analysts anticipate further revelations as incident investigations proceed and urge organizations across Africa and beyond to remain vigilant, especially those operating high-value or mission-critical infrastructure.

The compromise of government agencies, businesses, and educational entities highlights the pervasive threat posed by advanced attackers exploiting software weaknesses and the ongoing necessity of robust cybersecurity strategies in a rapidly evolving threat landscape.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories