SharePoint Patches Didn’t Clear BIT’s Breach

Patching on-prem SharePoint can close the bug and still leave an intruder trusted inside. If the attacker takes machine keys or account credentials, the server fix does not end the access problem; it just removes one path into a system that may already be compromised. Switzerland’s federal IT office BIT says about 200 user and technical accounts were exposed after attackers used recently disclosed SharePoint flaws that Microsoft fixed in mid-July. BIT saw unusual activity on July 28, blocked internet access to the platform, and reset passwords after confirming the intrusion; it says there is no evidence of leakage beyond login credentials, and the attack may involve CVE-2026-56164 or CVE-2026-50522. The risk now is persistence in the SharePoint trust layer. A patched server can still be dangerous if forged sign-ins or session tokens remain valid, which turns a web app flaw into an identity problem.

Part of the PlainSec briefing for 2026-08-07

Editions

Sources