Microsoft says Chinese hacking groups exploited SharePoint vulnerability in attacks

Microsoft says Chinese hacking groups exploited SharePoint vulnerability in attacks


Microsoft CEO Satya Nadella speaks during an event commemorating the 50th anniversary of the company at Microsoft headquarters in Redmond, Washington, on April 4, 2025. Microsoft Corp., determined to hold its ground in artificial intelligence, will soon let consumers tailor the Copilot digital assistant to their own needs.

David Ryder | Bloomberg | Getty Images

Microsoft on Tuesday said Chinese hacking groups were part of the recent attacks on its SharePoint collaboration software.

As early as July 7, the Chinese nation-state actors it calls Linen Typhoon and Violet Typhoon have been trying to exploit the vulnerability, as has a China-based actor called Storm-2603, Microsoft said in a Tuesday blog post.

On Monday, Charles Carmakal, technology chief of the Google-owned Mandiant cybersecurity consulting group, said in a LinkedIn post that “we assess that at least one of the actors responsible for the early exploitation is a China-nexus threat actor.”

On Sunday, the U.S. Cybersecurity and Infrastructure Security Agency said it was “aware of active exploitation” of the vulnerability, and Microsoft rolled out patches for two versions of its on-premises SharePoint releases. The software company issued a fix for a third version on Monday.

SharePoint is a key component of Microsoft’s widely used Office productivity software, enabling many people inside organizations to access internal files.

Last year, Microsoft CEO Satya Nadella made cybersecurity a top priority after a U.S. government report criticized the company’s handling of China’s breach of U.S. government officials’ email accounts.

Last week, the company said it would stop relying on engineers based in China to support the Pentagon’s use of cloud services, after a media report suggested that the architecture could have led to China-sponsored attacks against the U.S. defense arm.

In 2021, attackers affiliated with the Chinese nation-state group known as Hafnium targeted a different piece of Office software, Exchange Server, which provides mail and calendar services.

WATCH: Clode: Cybersecurity budgets won’t be the ones getting cut

Clode: Cybersecurity budgets won’t be the ones getting cut



Source

From data center spas to servers in space: How the energy crunch is reshaping cloud computing
Technology

From data center spas to servers in space: How the energy crunch is reshaping cloud computing

Lenovo in partnership with AKT II and Mamou-Mani imagines the data centers of the future: a data center spa James Cheung, partner at Mamou-Mani Artificial intelligence is advancing at breakneck speed, forcing a rethink of how the power-hungry servers behind the boom can coexist with — and draw less from — the environment. Data centers […]

Read More
One year on from the UK’s grand AI plan: has its infrastructure buildout been a success?
Technology

One year on from the UK’s grand AI plan: has its infrastructure buildout been a success?

QTS’s data center in Cambois, North East of England When the U.K. announced its AI Opportunities Action Plan — a grand blueprint to deploy the tech across society — in January, Prime Minister Keir Starmer declared the strategy would make the country an “AI superpower.”  One of the key pillars of this plan was a […]

Read More
New NASA boss Isaacman says U.S. will return to the moon within Trump’s term
Technology

New NASA boss Isaacman says U.S. will return to the moon within Trump’s term

Recently appointed NASA Administrator Jared Isaacman on Friday told CNBC that the U.S. will return to the moon within President Donald Trump’s second term. Isaacman, a close ally of SpaceX CEO Elon Musk, told CNBC’s “Closing Bell Overtime” that Trump’s recommitment to exploring the moon is key to unlocking the “orbital economy.” “We want to […]

Read More