Our takeSwiss government’s BIT had 200 accounts compromised after attackers exploited Microsoft SharePoint server vulnerabilities. Patch immediately if you self-host SharePoint (some enterprises); most small teams use the hosted version and can ignore this.Cyber Resilience desk
What this means for you — Security leader:Apply Microsoft's July 2026 SharePoint patches (including the two KEV items) immediately if you run on-prem SharePoint exposed to the internet; review and rotate the ~200 compromised credentials and inspect for further persistence.
What this means for you — Lean IT orgs:If you run your own on-prem Microsoft SharePoint server reachable from the internet, patch it with Microsoft's July 2026 updates this week and change any admin passwords.
What this means for you — MSP:Check every client running on-prem SharePoint for the July 2026 Microsoft patches (two are already exploited); apply them out-of-band where internet-facing and review affected accounts for compromise.
What this means for you — Researcher:The Swiss government BIT incident shows the Rapid7-published SharePoint PoC is already being used in targeted attacks; monitor for related scanning and credential abuse.