Tech News
← Home  ·  All topics

Sharepoint

5 GoKawiil briefs on this topic

Wire survey finds most security teams can't track who has access to shared M365 files

A Wire survey found that 61% of security leaders say access to shared files in Microsoft 365 often stays active far longer than intended, while more than a third struggle to even identify who currently has access to sensitive shared content. The report points to routine sharing habits—like adding freelancers to SharePoint folders or inviting new members into Teams channels—as common ways access quietly persists beyond its original purpose.

Microsoft 365 outage disrupts Outlook, OneDrive, Teams and SharePoint

Microsoft confirmed widespread service degradation across its 365 suite, affecting Outlook, OneDrive, SharePoint, Teams, Copilot and Universal Print. Users reported problems sending or receiving emails, loading files, and accessing print jobs, though Microsoft says availability has largely stabilized above 99 percent.

Azure OpenAI assistant leaked SharePoint files to low-privilege users, engineer finds

Egiziago Cioffi, CEO of Microsoft partner SynSphere Italia, discovered that an Azure OpenAI email assistant he built was returning SharePoint content to a low-privilege test account that the account could not access directly in SharePoint. The assistant had passed all evaluation scores and unit tests, but comparing outputs from a high-privilege and a low-privilege account against identical queries exposed the mismatch, revealing that retrieval was happening under the indexer's permissions rather than the requester's.

Microsoft 365 outage stretches into second day despite partial fixes

A multi-day outage tied to Microsoft's Exchange Online authentication system continues to disrupt Outlook and other Microsoft 365 services into Tuesday, even after Monday's mitigation efforts. Microsoft says the root cause was a misconfiguration preventing authentication components from deploying properly across parts of its infrastructure, affecting SharePoint, Teams, Copilot, Defender XDR, Purview, the admin center, and Universal Print alongside Outlook.

Attackers chain two Microsoft SharePoint flaws using public PoC exploits

Threat intelligence firm Defused reports that hackers are actively probing SharePoint servers by combining two vulnerabilities: an authentication bypass in JWT token validation (CVE-2026-55040) and a Business Connectivity Services flaw (CVE-2026-63520) that enables remote code execution. Proof-of-concept code for both bugs was published publicly in August by researchers at Rapid7 and VulnCheck, and Defused says it has already observed the bypass being exploited alongside admin enumeration on honeypots, though no successful code execution has been confirmed yet.