Breaking
July 23, 2025

Microsoft seemingly confirms Chinese hackers behind SharePoint server attacks | usagoldmines.com

  • Microsoft names three Chinese hacking groups it claims were abusing recently discovered flaws in SharePoint
  • Hackers were apparently able to access sensitive data
  • The company is confident the attacks will keep coming until the systems are patched

At least three major Chinese hacking groups were abusing recently discovered vulnerabilities to target businesses using Microsoft SharePoint, the company has said.

Microsoft recently released an urgent patch to fix two zero-day vulnerabilities affecting on-premises SharePoint servers, tracked as CVE-2025-49704 (a remote code execution bug), and CVE-2025-49706 (a spoofing vulnerability), which were being abused in the wild.

Now, Microsoft is saying that the groups targeting the flaws are Chinese state-sponsored groups – namely Linen Typhoon, Violet Typhoon, and Storm-2603.

Get Keeper’s Personal Password Manager plan for just $1.67/month

Keeper is a password manager with top-notch security. It’s fast, full-featured, and offers a robust web interface. The Personal Plan gets you unlimited password storage across all your devices, auto-login & autofill to save time, secure password sharing with trusted contacts, biometric login & 2FA for added security.View Deal

Two typhoons and a storm

The first two are part of the larger “typhoon” operation, counting at least half a dozen organizations, including Brass Typhoon, Salt Typhoon, Volt Typhoon, and Silk Typhoon.

In the last couple of years, these groups were attributed with breaches into critical infrastructure organizations, government, defense, and military firms, telecom operators, and similar businesses, across the western world and NATO members.

Some researchers are saying that these groups were tasked with persisting in the target networks, in case the standoff between the US and China over Taiwan escalates into actual war. That way, they would be able to disrupt or destroy critical infrastructure, eavesdrop on important conversations, and thus gain the upper hand in the conflict.

At least seven major telecommunications operators in the United States have recently confirmed discovering Typhoon operatives on their networks and removing them from the virtual premises.

“Investigations into other actors also using these exploits are still ongoing,” Microsoft said in a blog post, stressing that the attackers will definitely continue targeting unpatched systems.

SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 were said to be affected. SharePoint Online (Microsoft 365) was secure.

Microsoft recommends customers to use supported versions of on-premises SharePoint servers with the latest security updates immediately, and says users should ensure their antivirus and endpoint protection tools are up to date.

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.