Microsoft says it “has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting” the SharePoint zero-day vulnerabilities
Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting …
BleepingComputer Sergiu Gatlan
Related Coverage
- Disrupting active exploitation of on-premises SharePoint vulnerabilities Microsoft Security Blog
- Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day TechCrunch · Zack Whittaker
- Microsoft Says Chinese Hackers Exploiting SharePoint Flaws Bloomberg
- Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups CyberScoop · Matt Kapko
- Microsoft says Chinese hacking groups exploited SharePoint vulnerability in attacks CNBC · Jordan Novet
- Microsoft Says Chinese Hackers Are Exploiting SharePoint Flaws Bloomberg Law · Brody Ford
- Hackers Exploit Zero-Day Microsoft SharePoint Exploit, Attacking Governments and Businesses Around the World Daring Fireball · John Gruber
- Microsoft Fix Targets Attacks on SharePoint Zero-Day Krebs on Security · Brian Krebs
- Microsoft accuses Chinese hackers of exploiting SharePoint software Financial Times · Rafe Uddin
- Chinese cyber spies among those linked to SharePoint attacks ComputerWeekly.com · Alex Scroxton
- Microsoft pins on-prem SharePoint attacks on Chinese threat actors Help Net Security · Zeljka Zorz
- Microsoft knew of SharePoint server exploit but failed to effectively patch it Reuters · James Pearson
- Microsoft: Chinese State Hackers Target SharePoint Flaw in Stealthy Attacks CyberInsider · Bill Mann
- Mandiant: China-Linked Hackers Behind Recent Microsoft SharePoint Zero-Day Attacks WinBuzzer · Markus Kasanmascheff
- Proactive Security Insights for SharePoint Attacks (CVE-2025-53770 and CVE-2025-53771) Trend Micro
- Microsoft SharePoint hack: CERT-In flags ongoing threat, follow these steps to secure your systems The Indian Express
- Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day Cyber Security News · Guru Baran
- Hackers exploit SharePoint flaw to breach servers, Microsoft issues fix Business Standard · Rimjhim Singh
- SharePoint Zero-Day CVE-2025-53770 Actively Exploited: What Security Teams Need to Know Check Point Blog
- Respond and Remediate: A CISO's Guide to the SharePoint Zero-Day Vulnerabilities Fortified Health Security · Russell Teague
- Microsoft Releases Final Patch For SharePoint Server Against ‘ToolShell’ Attacks CRN · Kyle Alspach
- Microsoft SharePoint zero-day breach hits on-prem servers CSO · Gyana Swain
- Microsoft SharePoint servers are under attack because of a major security flaw The Verge · Jess Weatherbed
- “We're witnessing an urgent and active threat” — Microsoft SharePoint “ToolShell” vulnerability is being attacked globally Windows Central · Sean Endicott
- A Microsoft SharePoint 0-Day Security Vulnerability Was Just Weaponized At Scale HotHardware · Bruno Ferreira
- Microsoft confirms SharePoint server hack likely a single actor; thousands of firms at risk The American Bazaar · Nileena Sunil
- Attackers Exploiting Microsoft SharePoint Vulnerabilities Channel Futures · Edward Gately
- Microsoft releases emergency security updates to fix SharePoint zero-day flaws — everything you need to know Tom's Guide · Amber Bouman
- Microsoft SharePoint Zero-Day: Latest in a Concerning Pattern of On-Premises File Sharing Vulnerabilities Virtru · Matt Howard
- ‘Act now’: Hackers exploit Microsoft SharePoint vulnerability Information Age · Leonard Bernardone
- New Microsoft SharePoint exploit patched in emergency security update Notebookcheck · Rohith Bhaskar
- What to know about a vulnerability being exploited on Microsoft SharePoint servers Associated Press · Shawn Chen
- Hackers exploit Microsoft SharePoint “zero day” vulnerability Sherwood News · Jon Keegan
- Update now! Microsoft SharePoint is actively being exploited by hackers PCWorld · Michael Crider
- Microsoft issues emergency patches for SharePoint zero-days exploited in “ToolShell” attacks Security Affairs · Pierluigi Paganini
- Microsoft servers attacked: The zero-day exploit explained Digit · Vyom Ramani
- Three Chinese threat groups exploited SharePoint flaws, Microsoft Metacurity · Cynthia B Brumfield
- Microsoft flaw ‘opens the door’ for hackers. It will be hard to close SFGATE · Alex Halverson
- Google says some SharePoint hacks carried out by ‘China-nexus threat actor’ Reuters
- Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks BleepingComputer · Lawrence Abrams
- Microsoft Sharepoint server vulnerability puts an estimated 10,000 organizations at risk Engadget · Steve Dent
- Thousands of organizations at risk in latest Microsoft hacking spree Axios · Sam Sabin
- Hackers exploit Microsoft SharePoint as firm works to patch The Boston Globe
- Hackers exploiting SharePoint zero-day seen targeting government agencies TechCrunch · Lorenzo Franceschi-Bicchierai
- Microsoft server hack hit about 100 organisations, researchers say The Irish Times
- Mass Exploitation: Hackers Hit Zero-Day Flaw in Microsoft's SharePoint PCMag · Michael Kan
- Microsoft releases urgent fix for SharePoint zero-day vulnerability Mashable · Meera Navlakha
- Hackers use Microsoft security flaw to commit global assault UPI · Ian Stark
- Microsoft releases emergency fix for Sharepoint after cyberattacks CBS News
- Microsoft releases urgent fix for Sharepoint vulnerability being used in global cyberattacks Associated Press
- 10,000+ companies at risk from Microsoft Sharepoint security flaw 9to5Mac · Ben Lovejoy
- ACSC alerts to exploited MS SharePoint remote code execution flaw iTnews · Juha Saarinen
Discussion
-
@serghei@mastodon.social
Sergiu Gatlan
on mastodon
Microsoft links the SharePoint ToolShell attacks to three Chinese hacking groups: — Chinese nation-state threat groups Linen Typhoon and Violet Typhoon — China-based threat actor tracked as Storm-2603 — https://www.bleepingcomputer.com/ ...
-
@ericgeller
Eric Geller
on x
At least 3 Chinese hacker groups, two of them linked to Beijing, are exploiting the recently disclosed SharePoint vulnerabilities, according to Microsoft. Google confirms “a China-nexus threat actor” conducted early exploitation. https://www.microsoft.com/... https://www.linkedi…