Sunday, 26 October 2025
31.7 C
Singapore
30.8 C
Thailand
28.3 C
Indonesia
28.5 C
Philippines

Microsoft links SharePoint cyberattacks to Chinese state-backed hackers

Microsoft confirms Chinese hacking groups exploited a SharePoint vulnerability to breach dozens of organisations, and urges urgent patching.

Microsoft has confirmed that recent cyberattacks exploiting a vulnerability in its SharePoint server platform have been linked to hacking groups associated with the Chinese government. The announcement follows a series of breaches affecting various organisations, including academic, energy, and government institutions.

Chinese hacking groups identified

According to a blog post published by Microsoft on 23 July, the tech giant has identified several Chinese nation-state actors exploiting a zero-day vulnerability in SharePoint. Specifically, the hacking groups Linen Typhoon and Violet Typhoon have been observed targeting internet-facing SharePoint servers. A third group, known as Storm-2603, also based in China, has reportedly been involved in similar malicious activity.

“As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting these vulnerabilities targeting internet-facing SharePoint servers,” the company stated. “In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities. Investigations into other actors also using these exploits are still ongoing.”

Dozens of organisations are affected

Cybersecurity firm Eye Security reported to technology site BleepingComputer that it has so far identified 54 affected organisations. Among them are a private university, a California-based private energy provider, and a federal government health agency. The Washington Post also cited unnamed sources involved in the SharePoint investigation who indicated that some attacks could be traced to IP addresses located within China.

The vulnerability being exploited allows unauthorised access to on-premises SharePoint servers. Once infiltrated, attackers can extract sensitive information, harvest user credentials, and move laterally across connected systems. The flaw was first detailed by researchers at Eye Security last week, raising concerns about the potential scale and impact of these attacks.

Patch released, but risks remain

Microsoft issued a patch on the morning of 23 July for SharePoint 2016 servers. With this release, all affected versions of SharePoint are now covered by official security updates. However, the company has warned that the threat remains high, particularly for systems that have not yet been updated.

In a security update, Microsoft stated it believes “with high confidence” that the exploit will continue to be used against unpatched servers. The company urged administrators and organisations to apply the necessary updates immediately to prevent further breaches.

The incident underscores the ongoing cyber threat posed by state-sponsored groups and highlights the importance of timely security patching, particularly for widely used enterprise platforms like SharePoint.

Hot this week

XPENG Singapore celebrates 1,000th vehicle delivery milestone

XPENG Singapore marks its 1,000th vehicle delivery milestone and offers charging credits to celebrate its first anniversary in the market.

Major internet outage disrupts Fortnite, Nintendo and more after AWS failure

A major AWS outage disrupted Fortnite, Nintendo, and other online services worldwide, exposing the risks of centralised internet infrastructure.

Leica launches new M-mount camera that ditches the rangefinder

Leica unveils the M EV1, its first M-series camera with an electronic viewfinder, marking a bold step beyond its iconic rangefinder design.

AI disruption and quantum threats emerge as key risks for critical infrastructure security

Thales report warns AI disruption and quantum risks are reshaping cybersecurity for critical infrastructure despite falling breach rates.

Rubrik introduces Agent Cloud to accelerate secure enterprise AI adoption

Rubrik launches Agent Cloud, a new platform enabling enterprises to monitor, govern, and undo AI agent actions across major platforms.

Samsung One UI 8.5 may introduce a new notification prioritisation tool

Samsung’s upcoming One UI 8.5 update may include a new tool that prioritises important notifications to improve alert management.

Neato cloud shutdown leaves robot vacuums limited to manual operation

Neato’s cloud services are shutting down, leaving its robot vacuums without app control and limited to manual operation.

New Nomad Stratos Band blends titanium durability with everyday comfort

Nomad launches the Stratos Band, a hybrid Apple Watch band combining titanium and FKM rubber for durability and everyday comfort.

Red Hat: Building a secure foundation for hybrid cloud and AI in APAC

Red Hat Enterprise Linux 10 strengthens security and compliance for hybrid cloud and AI in APAC, helping enterprises navigate complex regulations.

Related Articles