/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says it “has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting” the SharePoint zero-day vulnerabilities

Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Microsoft’s attribution adds named actors to reporting that had already linked at least part of the SharePoint campaign to Chinese government-connected hackers, following the initial reporting on the RCE attacks.

The episode also echoes a previous SharePoint vulnerability targeted at U.S. municipalities and Microsoft’s 2021 warning about Chinese state-sponsored exploitation of Exchange zero-days, making the affected collaboration stack a recurring high-value target.

First-order effects

  • Organizations running affected SharePoint deployments must treat the vulnerabilities as actively exploited, prioritizing containment, patching or mitigation, and review for signs of compromise.
  • Microsoft’s public identification of Linen Typhoon and Violet Typhoon gives defenders concrete threat-actor context for incident triage and detection work.

Second-order effects

  • Security teams and vendors will shift attention from general vulnerability management to threat hunting and detections tailored to the reported SharePoint activity, increasing operational pressure on customers with exposed or unpatched systems.
  • The attribution raises the stakes for Microsoft’s enterprise customers: a platform flaw becomes an intelligence and security incident rather than solely an IT maintenance task.

Third-order effects

  • If repeat exploitation of Microsoft enterprise-server flaws persists, buyers are likely to place greater weight on rapid patchability, exposure reduction, and vendor incident transparency when assessing collaboration infrastructure.
  • The pattern points to sustained nation-state interest in widely deployed enterprise software as an access route, with public attribution increasingly becoming part of how vendors coordinate defensive response.

The trend: This is one instance of nation-state operators repeatedly exploiting high-value enterprise collaboration software before defenders can fully close exposure.

Discussion

  • @serghei@mastodon.social Sergiu Gatlan on mastodon
    Microsoft links the SharePoint ToolShell attacks to three Chinese hacking groups:  — Chinese nation-state threat groups Linen Typhoon and Violet Typhoon  — China-based threat actor tracked as Storm-2603  —  https://www.bleepingcomputer.com/ ...
  • @ericgeller Eric Geller on x
    At least 3 Chinese hacker groups, two of them linked to Beijing, are exploiting the recently disclosed SharePoint vulnerabilities, according to Microsoft. Google confirms “a China-nexus threat actor” conducted early exploitation. https://www.microsoft.com/... https://www.linkedi…