Wednesday, 23 July 2025
30.5 C
Singapore
32 C
Thailand
23.1 C
Indonesia
27.3 C
Philippines

Microsoft links SharePoint cyberattacks to Chinese state-backed hackers

Microsoft confirms Chinese hacking groups exploited a SharePoint vulnerability to breach dozens of organisations, and urges urgent patching.

Microsoft has confirmed that recent cyberattacks exploiting a vulnerability in its SharePoint server platform have been linked to hacking groups associated with the Chinese government. The announcement follows a series of breaches affecting various organisations, including academic, energy, and government institutions.

Chinese hacking groups identified

According to a blog post published by Microsoft on 23 July, the tech giant has identified several Chinese nation-state actors exploiting a zero-day vulnerability in SharePoint. Specifically, the hacking groups Linen Typhoon and Violet Typhoon have been observed targeting internet-facing SharePoint servers. A third group, known as Storm-2603, also based in China, has reportedly been involved in similar malicious activity.

“As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting these vulnerabilities targeting internet-facing SharePoint servers,” the company stated. “In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities. Investigations into other actors also using these exploits are still ongoing.”

Dozens of organisations are affected

Cybersecurity firm Eye Security reported to technology site BleepingComputer that it has so far identified 54 affected organisations. Among them are a private university, a California-based private energy provider, and a federal government health agency. The Washington Post also cited unnamed sources involved in the SharePoint investigation who indicated that some attacks could be traced to IP addresses located within China.

The vulnerability being exploited allows unauthorised access to on-premises SharePoint servers. Once infiltrated, attackers can extract sensitive information, harvest user credentials, and move laterally across connected systems. The flaw was first detailed by researchers at Eye Security last week, raising concerns about the potential scale and impact of these attacks.

Patch released, but risks remain

Microsoft issued a patch on the morning of 23 July for SharePoint 2016 servers. With this release, all affected versions of SharePoint are now covered by official security updates. However, the company has warned that the threat remains high, particularly for systems that have not yet been updated.

In a security update, Microsoft stated it believes “with high confidence” that the exploit will continue to be used against unpatched servers. The company urged administrators and organisations to apply the necessary updates immediately to prevent further breaches.

The incident underscores the ongoing cyber threat posed by state-sponsored groups and highlights the importance of timely security patching, particularly for widely used enterprise platforms like SharePoint.

Hot this week

Google reveals Pixel 10 design ahead of official launch

Google teases the Pixel 10’s design ahead of its 20 August launch, showing a new rear camera and a familiar look in an early promotional video.

Apple launches online retail store in Saudi Arabia for the first time

Apple launches its official online store in Saudi Arabia with Arabic support, direct sales, and plans for a retail store by 2026.

Samsung introduces new Smart Monitor range featuring first OLED M9 model

Samsung launches a new Smart Monitor range, featuring the first OLED M9 model and refreshed M8 and M7 models with AI and productivity upgrades.

Agentic AI: The journey from automation to autonomy

Explore the rise of agentic AI, its technological advancements, real-world applications, and challenges in achieving safe, reliable, and autonomous decision-making systems.

Microsoft unveils Intel-powered Surface Laptop 5G, shipping from 26 August

Microsoft’s new Surface Laptop 5G launches on 26 August, offering built-in 5G, AI features, and Intel Ultra chips starting from US$1,799.

AMD and Stability AI launch BF16 NPU model for Stable Diffusion 3.0 Medium

AMD and Stability AI launch the world’s first BF16 SD 3.0 Medium model for Ryzen AI laptops, now available in Amuse 3.1.

Borderlands 4 set for Nintendo Switch 2 release on 3 October

Borderlands 4 launches on Nintendo Switch 2 on 3 October, following its main release on PlayStation, Xbox and PC in September 2025.

Temus supports Singapore businesses in adopting AI with AWS AI Springboard programme

Temus helps Singapore enterprises adopt practical AI solutions through AWS AI Springboard, with support for 300 businesses.

Amazon acquires AI wearable startup Bee to boost personal assistant technology

Amazon acquires AI wearable startup Bee to enhance its personal assistant technology and strengthen its position in the AI wearables market.

Related Articles

Popular Categories