Tuesday, 9 September 2025
29.8 C
Singapore
28.1 C
Thailand
20.6 C
Indonesia
27.9 C
Philippines

Microsoft links SharePoint cyberattacks to Chinese state-backed hackers

Microsoft confirms Chinese hacking groups exploited a SharePoint vulnerability to breach dozens of organisations, and urges urgent patching.

Microsoft has confirmed that recent cyberattacks exploiting a vulnerability in its SharePoint server platform have been linked to hacking groups associated with the Chinese government. The announcement follows a series of breaches affecting various organisations, including academic, energy, and government institutions.

Chinese hacking groups identified

According to a blog post published by Microsoft on 23 July, the tech giant has identified several Chinese nation-state actors exploiting a zero-day vulnerability in SharePoint. Specifically, the hacking groups Linen Typhoon and Violet Typhoon have been observed targeting internet-facing SharePoint servers. A third group, known as Storm-2603, also based in China, has reportedly been involved in similar malicious activity.

“As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting these vulnerabilities targeting internet-facing SharePoint servers,” the company stated. “In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities. Investigations into other actors also using these exploits are still ongoing.”

Dozens of organisations are affected

Cybersecurity firm Eye Security reported to technology site BleepingComputer that it has so far identified 54 affected organisations. Among them are a private university, a California-based private energy provider, and a federal government health agency. The Washington Post also cited unnamed sources involved in the SharePoint investigation who indicated that some attacks could be traced to IP addresses located within China.

The vulnerability being exploited allows unauthorised access to on-premises SharePoint servers. Once infiltrated, attackers can extract sensitive information, harvest user credentials, and move laterally across connected systems. The flaw was first detailed by researchers at Eye Security last week, raising concerns about the potential scale and impact of these attacks.

Patch released, but risks remain

Microsoft issued a patch on the morning of 23 July for SharePoint 2016 servers. With this release, all affected versions of SharePoint are now covered by official security updates. However, the company has warned that the threat remains high, particularly for systems that have not yet been updated.

In a security update, Microsoft stated it believes “with high confidence” that the exploit will continue to be used against unpatched servers. The company urged administrators and organisations to apply the necessary updates immediately to prevent further breaches.

The incident underscores the ongoing cyber threat posed by state-sponsored groups and highlights the importance of timely security patching, particularly for widely used enterprise platforms like SharePoint.

Hot this week

Gen Z drives AI adoption at work by coaching older colleagues

Gen Z workers are driving AI adoption by coaching older colleagues, boosting productivity, collaboration, and career growth across generations.

Xero launches new AI features in JAX to support small business accounting

Xero unveils new AI features in its JAX platform, offering automation, insights, and secure support for small businesses worldwide.

Veeam launches first software appliance for instant, secure data protection

Veeam has launched its first hardware-agnostic software appliance, offering instant, secure data protection with built-in resilience.

Neo4j launches Infinigraph as most scalable graph database

Neo4j launches Infinigraph, a new graph database architecture designed to unify transactions and analytics at over 100TB scale.

Lenovo unveils AI-powered portfolio across PCs, gaming, tablets and smartphones

Lenovo showcases its full AI-powered portfolio at IFA 2025, unveiling new PCs, tablets, gaming devices, and Motorola smartphones.

Firefox introduces shake to summarise feature on iPhones

Firefox launches a new “shake to summarise” feature on iPhones, offering AI-powered webpage summaries starting in the US.

Google pauses Pixel 10 Daily Hub to improve performance

Google has paused the Pixel 10’s Daily Hub feature to improve performance, promising a refined version will return in the future.

Garmin launches fēnix 8 MicroLED smartwatch with record-breaking brightness

Garmin unveils the fēnix 8 MicroLED, the world’s brightest smartwatch with advanced health, navigation, and performance features.

OpenAI set to develop its own AI chips in 2025

OpenAI is reportedly set to develop its own AI chips with Broadcom in 2025, aiming to reduce reliance on NVIDIA and expand capacity.

Related Articles

Popular Categories