B
今週中
スイス連邦情報技術通信局(FOITT)のオンプレミスSharePointサーバーが攻撃を受け、約200のアカウントが侵害されました
📌 一言でいうと
スイス連邦情報技術通信局(FOITT)のオンプレミスSharePointサーバーが攻撃を受け、約200のアカウントが侵害されました。攻撃者はMicrosoft SharePointの脆弱性を悪用したと考えられており、FOITTは現在サーバーの再構築と調査を進めています。Microsoftは7月中旬にSharePointに関する複数の脆弱性を報告していました。
🔍該当判定
- 自社でSharePointのサーバーを物理的に所有、または仮想サーバーで運用している(オンプレミス版の利用)
- Microsoft 365(クラウド版)ではなく、社内サーバーにインストールしたSharePointを利用している
- 2026年7月中旬に公開されたSharePointのセキュリティ更新プログラムをまだ適用していない
上記いずれにも該当しない(例:クラウド版のSharePoint Onlineのみ利用している) → 静観でOK
✅該当時の対応
オンプレミス版Microsoft SharePointを利用している組織は、最新のセキュリティ更新プログラムを適用し、不審なアカウントアクティビティがないかログを確認することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Microsoft SharePoint 脆弱性悪用による侵害事例について
お疲れさまです。スイス連邦政府機関におけるSharePointの脆弱性を悪用した侵害事例に関する情報共有です。
■ 概要
スイスの連邦情報技術通信局(FOITT)において、オンプレミス版SharePointの脆弱性が悪用され、約200のアカウントが侵害されました。Microsoftが7月中旬に公開した脆弱性が利用された可能性が高いとされています。
■ 影響範囲
- 対象製品: Microsoft SharePoint (On-premises)
■ 対応手順
1. Microsoftからリリースされている最新の累積更新プログラム (CU) およびセキュリティ更新プログラムを適用してください。
2. 特権アカウントを含むSharePoint上のアカウントに不審なログインや権限変更がないか監査ログを確認してください。
■ 参考情報
- Microsoft Security Update Guide
対応優先度: 高
対応期限: 速やかに
お疲れさまです。スイス連邦政府機関におけるSharePointの脆弱性を悪用した侵害事例に関する情報共有です。
■ 概要
スイスの連邦情報技術通信局(FOITT)において、オンプレミス版SharePointの脆弱性が悪用され、約200のアカウントが侵害されました。Microsoftが7月中旬に公開した脆弱性が利用された可能性が高いとされています。
■ 影響範囲
- 対象製品: Microsoft SharePoint (On-premises)
■ 対応手順
1. Microsoftからリリースされている最新の累積更新プログラム (CU) およびセキュリティ更新プログラムを適用してください。
2. 特権アカウントを含むSharePoint上のアカウントに不審なログインや権限変更がないか監査ログを確認してください。
■ 参考情報
- Microsoft Security Update Guide
対応優先度: 高
対応期限: 速やかに
Subject: [Security Alert] Compromise of Microsoft SharePoint via Vulnerabilities
Dear IT/Security Team,
We are sharing information regarding a recent security breach at Switzerland's Federal Office for Information Technology and Communications (FOITT).
■ Overview
Attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise approximately 200 accounts. The attack is linked to vulnerabilities reported by Microsoft in mid-July.
■ Scope
- Affected Product: Microsoft SharePoint (On-premises)
■ Action Items
1. Ensure all on-premises SharePoint servers are updated with the latest security patches and Cumulative Updates (CU).
2. Review audit logs for any unauthorized account access or privilege escalation within the SharePoint environment.
■ Reference
- Microsoft Security Update Guide
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a recent security breach at Switzerland's Federal Office for Information Technology and Communications (FOITT).
■ Overview
Attackers exploited vulnerabilities in on-premises Microsoft SharePoint servers to compromise approximately 200 accounts. The attack is linked to vulnerabilities reported by Microsoft in mid-July.
■ Scope
- Affected Product: Microsoft SharePoint (On-premises)
■ Action Items
1. Ensure all on-premises SharePoint servers are updated with the latest security patches and Cumulative Updates (CU).
2. Review audit logs for any unauthorized account access or privilege escalation within the SharePoint environment.
■ Reference
- Microsoft Security Update Guide
Priority: High
Deadline: Immediate