Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks

2026-04-22T07:23:31Zf95970d2606615f5fe0d4d1a12652f4a9903a1c69aed3b8daa1155b23f7f9354
android-malwareapache-activemqapple-app-storecatalyst-sd-wancisacode-injectioncrypto-heistcrypto-wallet-frauddata-breachfrance-titresgentlemen-ransomwarehandypaykelpdaolazaruslotus-wipermicrosoft-teams-impersonation','helpdesk-impersonation','csam','nfc-payment-theftngateseikosharepointspoofingsystembcvenezuelawebsite-defacementzero-day

What happened

Collection of security news covering multiple active and high-impact incidents: over 1,300 Microsoft SharePoint servers remain unpatched for a spoofing zero-day being actively exploited; CISA flagged a Catalyst SD‑WAN Manager flaw with urgent mitigation guidance; more than 6,400 Apache ActiveMQ servers are exposed to an actively exploited code‑injection vulnerability. Other notable items include a French government agency breach (France Titres), a previously undocumented Lotus data wiper used against Venezuelan energy/utility firms, a $290M KelpDAO heist likely tied to Lazarus, a trojanized NG

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f95970d2606615f5fe0d4d1a12652f4a9903a1c69aed3b8daa1155b23f7f9354
Enrichment time
2026-04-22T07:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.