---
title: "CISA Warns SharePoint, SimpleHelp Auth Bypass, Russian Spies Target  | DMARC Report"
description: "CISA warns of critical SharePoint and SimpleHelp authentication bypass flaws as Russian spies target organizations with cyberattacks."
image: "https://dmarcreport.com/og/blog/cisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target.png"
canonical: "https://dmarcreport.com/blog/cisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target/"
---

Quick Answer

CISA has warned about critical SharePoint and SimpleHelp authentication bypass vulnerabilities while highlighting Russian cyber espionage activity targeting organizations. Businesses should patch affected systems, strengthen access controls, and monitor for signs of compromise.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fcisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=CISA%20Warns%20SharePoint%2C%20SimpleHelp%20Auth%20Bypass%2C%20Russian%20Spies%20Target%20&url=undefined%2Fblog%2Fcisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fcisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fcisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target%2F&title=CISA%20Warns%20SharePoint%2C%20SimpleHelp%20Auth%20Bypass%2C%20Russian%20Spies%20Target%20 "Share on Reddit") [ ](mailto:?subject=CISA%20Warns%20SharePoint%2C%20SimpleHelp%20Auth%20Bypass%2C%20Russian%20Spies%20Target%20&body=Check out this article: undefined%2Fblog%2Fcisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target%2F "Share via Email") 

![cybersecurity threat warning](https://media.mailhop.org/dmarcreport/dmarc-check-7207-1783505019614.jpg) 

## CISA flags actively exploited SharePoint RCE (CVE-2026-45659)

A high-severity remote code execution flaw in on-premises SharePoint Server, caused by deserialization of untrusted data, was patched by **Microsoft in May 2026**, and [CISA](https://www.msn.com/en-us/news/insight/cisa-warns-of-active-sharepoint-flaw-exploitation/gm-GM7D30C485?gemSnapshotKey=GM7D30C485-snapshot-0&uxmode=ruby) added it to the Known Exploited Vulnerabilities catalog after confirming active exploitation, with [federal agencies](https://www.investopedia.com/terms/f/federal-agencies.asp) given until July 4 to patch. _Good “patch now” angle for your readers, especially since Microsoft originally rated it “exploitation less likely.”_

## SimpleHelp RMM auth bypass used to hit MSPs (CVE-2026-48558)

An attacker exploited a flaw in SimpleHelp’s OpenID Connect login to forge a technician session on an [internet-facing server](https://www.securityweek.com/hundreds-of-internet-facing-vnc-servers-expose-ics-ot/), then used the platform’s own file-transfer and **remote-execution features** to deploy malware researchers dubbed [TaskWeaver and Djinn Stealer](https://thehackernews.com/2026/06/attackers-exploit-simplehelp-cve-2026.html). Strong supply-chain-risk story for [MSP-focused readers](https://www.bell-integration.com/managed-service-providers-in-reading/).![Dmarc Report 9004](https://media.mailhop.org/dmarcreport/dmarc-report-9004-1783505311297.jpg)

## FBI/CISA: Russian spies now stealing Signal Backup Recovery Keys

Russian intelligence-linked hackers have shifted from hijacking Signal accounts to tricking targets into handing over [Signal Backup Recovery Keys](https://cyberinsider.com/us-offers-10-million-for-info-on-russian-hackers-targeting-signal-accounts/), which let attackers restore an account’s full historical message archive. _The State Department is offering a **$10 million** reward for information on the group known as UNC5792._ Great topic tying encryption strength to human social-engineering weakness — very on-brand for a [DMARC](https://dmarcreport.com/)/email-security audience.

## Alleged Scattered Spider member extradited to Chicago

Peter Stokes, 19, a dual **US-Estonian** citizen and [alleged Scattered Spider member](https://www.bbc.com/news/articles/cwy0we4yw1lo), was extradited from Finland and charged with conspiracy, cyber intrusion, and fraud in a complaint unsealed July 1\. _The complaint describes a May 2025 intrusion against a luxury jewelry retailer where the group demanded roughly $8 million in cryptocurrency._ ![Dmarc Analyzer 3407](https://media.mailhop.org/dmarcreport/dmarc-analyzer-3407-1783505615143.jpg)

## Nissan discloses employee data breach tied to Oracle zero-day

[Nissan disclosed a data breach](https://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/) affecting **current and former employees** after [threat actors](https://www.darkreading.com/ics-ot-security/iranian-threat-actors-us-critical-infrastructure-exposed-plcs) exploited an Oracle PeopleSoft vulnerability in attacks previously linked to the ShinyHunters extortion group.

## KDDI breach exposes 14.2 million logins across six Japanese ISPs

Japanese telecom KDDI disclosed a breach of an **email system** used by five other [ISPs](https://www.investopedia.com/terms/i/isp.asp) (STNet, JCom, Chubu Telecommunications, NIFTY, and BIGLOBE), potentially exposing email addresses and passwords for up to [14.22 million](https://www.techrepublic.com/fr/article/news-kddi-breach-isp-email-accounts-apac-japan/) customers.

## NAIC says only public data taken in ShinyHunters PeopleSoft breach

The **National Association of Insurance Commissioners** says ShinyHunters stole only publicly available data, outdated logs and configuration files after exploiting a zero-day in an Oracle PeopleSoft server — despite the group’s own claims of [3.1 TB stolen](https://www.insurancebusinessmag.com/us/news/cyber/3-1tb-of-naic-data-dumped-on-to-the-dark-web-580537.aspx).

## Nidec hit with $2 million ransomware demand

The [Blackfield ransomware gang](https://www.secnews.gr/en/718276/blackfield-litra-nidec-ransomware-epithesi/) is demanding $2 million from Nidec Corporation, a major Japanese manufacturer of electronic components for **automotive and computing applications**.![What Is Dmarc 9703](https://media.mailhop.org/dmarcreport/what-is-dmarc-9703-1783505813996.jpg)

## Check Point tests whether AI models will build ransomware tools

Check Point Research published an analysis of an experiment with the [DeepSeek AI model](https://www.cnbc.com/2026/07/07/chinese-ai-models-costs-us-openai-anthropic.html), in which researchers asked it to build a “file encryption tool” for a web page — a timely **AI-safety angle** showing how quickly a model can produce ransomware-adjacent code.

## ”Mistic” — a self-erasing, memory-only backdoor

A self-destructing, [memory-only backdoor](https://www.techtimes.com/articles/319075/20260625/fileless-ransomware-backdoor-mistic-erases-itself-symantec-warns-file-scans-will-miss-it.htm) designed specifically so incident responders won’t find it has been tied to an initial-access-broker market selling dwell-time access for ransomware deployment.

## Citrix patches NetScaler flaws including new “HTTP/2 Bomb” attack

Citrix released fixes for six [NetScaler vulnerabilities](https://www.securityweek.com/citrix-patches-netscaler-vulnerabilities-including-new-http-2-bomb-attack/), including a novel HTTP/2 Bomb denial-of-service flaw and a **CitrixBleed-style information** disclosure bug — worth flagging since CitrixBleed-class issues have a history of mass exploitation.

## Klue/Icarus SaaS supply-chain breach hits nine security firms

![Dmarc Check 9702](https://media.mailhop.org/dmarcreport/dmarc-check-9702-1783505923017.jpg)The [Klue/Icarus SaaS supply-chain breach](https://www.cybersecuritydive.com/news/klue-investigating-supply-chain-attack-salesforce-integrations/823532/), in which an attacker who compromised a trusted **third-party platform** used established trust relationships rather than breaching each victim’s perimeter directly, exposed data at HackerOne, LastPass, and other companies whose Klue/Salesforce integrations were compromised.

## Tchap, the French government’s Signal alternative, gets hacked

Tchap, a messaging app built by [France’s DINUM and ANSSI](https://thecyberexpress.com/tchap-breach-french-government/) for government use after **foreign chat apps** were banned for official work, was hacked in June, with an attacker claiming to have stolen 13.5 GB of data, including tens of thousands of user accounts and government personnel messages — a nice irony angle (a “secure alternative” getting breached).

## Medtronic notifies customers after third-party data exposure

Healthcare device maker Medtronic began notifying customers about a breach that [exposed their personal data](https://securityaffairs.com/194788/cyber-crime/medtronic-notifies-3-8-million-after-shinyhunters-data-breach.html) to an unauthorized third party, adding to the steady drumbeat of healthcare-sector incidents this year. **Protect customers** with [SPF](https://dmarcreport.com/what-is-spf/), [DKIM](https://dmarcreport.com/what-is-dkim/), and DMARC to strengthen [cybersecurity](https://dmarcreport.com/blog/major-cybersecurity-trends-that-will-reign-in-2024/) and prevent [email spoofing](https://www.infosecurity-magazine.com/news/infosec2025-email-domains-spoofing/).

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

## Related Articles

[  Intermediate 4m  10 Reasons Why DKIM Fails  Apr 19, 2022 ](/blog/10-reasons-why-dkim-fails/)[  Intermediate  Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows  Jul 14, 2026 ](/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/)[  Intermediate 8m  Best DMARC Reporting Tools in 2026: Honest Comparison  Mar 25, 2026 ](/blog/best-dmarc-reporting-tools-2026/)[  Intermediate 12m  DMARC Passed. The Email Was Still an Attack. Inside the Blesta Ransom Incident  Jun 28, 2026 ](/blog/blesta-ransom-email-dmarc-passed-authenticated-abuse/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"CISA Warns SharePoint, SimpleHelp Auth Bypass, Russian Spies Target ","description":"CISA warns of critical SharePoint and SimpleHelp authentication bypass flaws as Russian spies target organizations with cyberattacks.","url":"https://dmarcreport.com/blog/cisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target/","datePublished":"2026-07-08T00:00:00.000Z","dateModified":"2026-07-08T00:00:00.000Z","dateCreated":"2026-07-08T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/cisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-check-7207-1783505019614.jpg","caption":"cybersecurity threat warning"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://dmarcreport.com/intermediate/"},{"@type":"ListItem","position":4,"name":"CISA Warns SharePoint, SimpleHelp Auth Bypass, Russian Spies Target ","item":"https://dmarcreport.com/blog/cisa-warns-sharepoint-simplehelp-auth-bypass-russian-spies-target/"}]}
```
