Source: the US National Nuclear Security Administration was among those breached by a hack of SharePoint; no sensitive information is known to be compromised
The US agency responsible for maintaining and designing the nation's cache of nuclear weapons was among those breached by a hack …
Bloomberg Ari Natter
Context & Ripple Effects
The reported NNSA intrusion places a nuclear-weapons stewardship agency within a broader SharePoint incident that had already reached an estimated 400 government and corporate organizations. The reported absence of known sensitive-data compromise is an important but preliminary boundary on the incident’s disclosed impact.
NNSA had previously been identified among Energy Department networks accessed in the SolarWinds intrusion. The recurrence underscores how compromise of widely deployed enterprise software can reach agencies whose most sensitive operations may sit behind separate controls.
First-order effects
- NNSA must investigate affected SharePoint systems, contain access, and determine whether the intrusion reached systems or data beyond those currently known to be non-sensitive.
- Microsoft and organizations using the affected SharePoint deployment face immediate pressure to patch, hunt for signs of compromise, and validate that remediation removed attacker access.
Second-order effects
- The expanding victim count makes incident response a shared operational burden across public agencies and enterprises, increasing the value of coordinated detection and remediation rather than organization-by-organization action.
- For high-consequence agencies, the episode is likely to intensify scrutiny of how collaboration platforms are segmented from sensitive environments and how quickly security alerts reach defenders.
Third-order effects
- If repeated compromises of common enterprise platforms continue, security assurance will increasingly depend on ecosystem-wide response capacity—vendor disclosure, patch distribution, and customer telemetry—not only on an individual agency’s perimeter defenses.
- The pattern may push critical public-sector users toward stronger isolation and verification requirements for broadly deployed productivity software, although the disclosed facts do not establish whether current controls failed beyond initial access.
The trend: This is one data point in the shift from isolated cyber incidents to ecosystem-level risk management for ubiquitous enterprise software.
Related: Ecosystem cyber defense · SharePoint · US National Nuclear Security Administration · SharePoint flaw breaches about 400 organizations · Energy Department and NNSA in the SolarWinds hack
Related Coverage
- Report: Hacker Used SharePoint Flaw to Breach US Nuclear Agency PCMag · Michael Kan
- US nuclear weapons agency reportedly hacked in SharePoint attacks BleepingComputer · Sergiu Gatlan
- US agency overseeing nuclear weapons breached in Microsoft SharePoint attack Windows Central · Sean Endicott
- Victims Mounting In Microsoft SharePoint Attacks: Researchers CRN · Kyle Alspach
- Microsoft says China-backed cybercriminals hacked into US nuclear weapons agency New York Post · Ariel Zilber
- U.S. nuclear weapons department compromised in SharePoint attack Neowin · Usama Jawad
- US agency overseeing cache of nuclear weapons was breached in SharePoint attack Metacurity · Cynthia B Brumfield
- US nuclear weapons agency breached using Microsoft SharePoint hack Engadget · Steve Dent
- Chinese hackers suspected of breaching US nuclear weapons agency Telegraph · James Titcomb
- Microsoft confirms SharePoint vulnerabilities have been exploited by suspected Chinese hackers, as reports indicate the US Nuclear Security Administration may have been among those compromised PC Gamer · Andy Edser
- China-Backed Hackers Breach Key American Nuclear Agency IJR
- US Nuclear Agency Breach Tied to SharePoint Zero-Days DataBreachToday.com · Mathew J. Schwartz
- US nuclear weapons agency reportedly breached in Microsoft SharePoint attacks The Verge · Tom Warren
- Zero-Day Exploit Hits U.S. Nuclear Systems as Chinese Cyber Campaign Spreads Worldwide implicator.ai · Maria Garcia
- US nuclear agency hit in Microsoft server vulnerability hack Gizchina.com · Efe Udin
- US Nuclear Weapons Agency Breached by Hackers Using Microsoft SharePoint 0-Day Vulnerability Cyber Security News · Guru Baran
- US nuclear weapons agency ‘among 400 organisations breached by Chinese hackers’ The Guardian · Joanna Partridge
- Hundreds of organizations breached by SharePoint mass-hacks TechCrunch · Zack Whittaker
- Microsoft server hack has now hit 400 victims, researchers say Reuters · Raphael Satter
- The Microsoft SharePoint breach was massive. The response has been minimal Fast Company · Chris Stokel-Walker
- The Collapse of the Click: How Google's AI Is Reshaping Online Information implicator.ai · Marcus Schuler
- Assume breach: Critical SharePoint flaws under mass attack, warns Unit 42 Intelligent CIO · Sindhu Kashyap
- Eye Security Chief Hacker Vaisha Bernard to Bloomberg: Eye Security identified over 400 hacks at government agencies and corporations because of the Sharepoint vulnerability. … Job Kuijpers
- Disrupting active exploitation of on-premises SharePoint vulnerabilities Microsoft Security Blog
- Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities CISA
- Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows Reuters · James Pearson
- SharePoint 0-day uncovered (CVE-2025-53770) Eye Research
- Microsoft linked attacks on SharePoint flaws to China-nexus actors Security Affairs · Pierluigi Paganini
- Chinese Hackers Are Exploiting Flaws in Widely Used Software, Microsoft Says New York Times · Vivian Wang
- CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild Cyber Security News · Guru Baran
- Microsoft servers hacked by Chinese groups, says tech giant BBC
- Chinese state-backed hackers exploiting new SharePoint flaws, says Microsoft Moneycontrol
- Microsoft finds China-linked hackers are targeting SharePoint deployments SiliconANGLE · Maria Deutscher
- Microsoft grapples with another security breach: The latest on the SharePoint attacks GeekWire · Todd Bishop
- Microsoft Says China-Linked Hackers Are Behind SharePoint Attacks. What to Know. Barron's Online · Nate Wolf
- Hackers Exploit Microsoft SharePoint Flaws in Global Breaches Hackread · Deeba Ahmed
- Microsoft says Chinese hacking groups are behind SharePoint attacks The Verge · Jess Weatherbed
- Microsoft accuses Chinese hackers of exploiting SharePoint software Financial Times · Rafe Uddin
- Microsoft SharePoint zero-day attacks pinned on China-linked ‘Typhoon’ threat groups CyberScoop · Matt Kapko
Discussion
-
@gregotto
Greg Otto
on bluesky
Interested to hear how an on-prem SharePoint vuln was used to get into the NNSA when the NNSA said it's Microsoft instances are mainly cloud
-
@troynovaunt
@troynovaunt
on bluesky
Sharepoint? That thing that is always downloading the wrong cached version of the faculty handbook and keeps giving me access to random files from other offices on campus? That SharePoint? [embedded post]
-
@peark.es
George Pearkes
on bluesky
I don't know why I'm surprised that we're running SharePoints for nukes because I really shouldn't be — *US NUCLEAR WEAPONS AGENCY BREACHED IN MICROSOFT SHAREPOINT HACK
-
@liz.sheshed.rocks
@liz.sheshed.rocks
on bluesky
Microsoft knew of SharePoint server exploit but failed to effectively patch it. — Ongoing attacks compromised around 100 organizations over the weekend. — SharePoint's vulnerability was identified during hacker competition. — www.reuters.com/sustainabili...
-
@jordihays
Jordi Hays
on x
1) Microsoft discovers SharePoint vulnerability at a hacking competition in May 2) Patch meant to fix the issue doesn't work 3) US Nuclear Weapons program compromised in July Nice [image]
-
@geiger_capital
@geiger_capital
on x
*US NUCLEAR WEAPONS AGENCY BREACHED IN MICROSOFT SHAREPOINT HACK American companies need to get serious... Microsoft was using engineers in China, Chinese nationals, to help maintain computer systems in the Department of Defense. [image]
-
@aidangomez
Aidan Gomez
on x
COHERE IS PRIVATELY DEPLOYABLE AND ALSO CAN EVEN GO AIR GAPPED
-
@ddimolfetta
David DiMolfetta
on x
🇨🇳SharePoint vulnerability update: “We assess that at least one of the actors responsible for this early exploitation is a China-nexus threat actor,” Mandiant/Google Cloud CTO Chalres Carmakal says in a statement sent to me just now. My earlier reporting: https://www.nextgov.com/…
-
@ericgeller
Eric Geller
on x
Hackers reportedly breached the National Nuclear Security Administration and other parts of the Department of Energy through the Microsoft SharePoint vulnerability. https://www.bloomberg.com/... [image]
-
@arinatter
Ari Natter
on x
SCOOP: The US agency responsible for maintaining the nation's stockpile of nuclear weapons was among those breached by hackers exploiting Microsoft's SharePoint. [image]
-
r/cybersecurity
r
on reddit
US Nuclear Weapons Agency Breached in Microsoft SharePoint Hack
-
@aelkus
@aelkus
on bluesky
there are people here in DC who have entire businesses built around classified sharepoint management
-
@pits666
@pits666
on bluesky
She said that she felt vulnerable. — He said not as vulnerable as on-prem SharePoint right now. — #nerdromancewithpits
-
@wylienewmark
@wylienewmark
on bluesky
back in the day, attribution of widespread exploitation of a vulnerability in a ubiquitous piece of software used *kinda* up in the air. now, a guess of “China” has roughly a 60% chance of being correct.
-
@serghei@mastodon.social
Sergiu Gatlan
on mastodon
Microsoft links the SharePoint ToolShell attacks to three Chinese hacking groups: — Chinese nation-state threat groups Linen Typhoon and Violet Typhoon — China-based threat actor tracked as Storm-2603 — https://www.bleepingcomputer.com/ ...
-
@msftsecintel
@msftsecintel
on x
Microsoft is sharing details from ongoing investigations of threat actors exploiting vulnerabilities targeting on-premises SharePoint servers. Linen Typhoon, Violet Typhoon, and Storm-2603 have been observed exploiting the vulnerabilities: https://www.microsoft.com/...
-
@cglyer
Christopher Glyer
on x
MSTIC blog on Sharepoint exploitation At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7: Linen Typhoon Violet Typhoon Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown) https://www.microsoft.com/...
-
@cglyer
Christopher Glyer
on x
You can find Microsoft's mapping of the most common threat actors at https://aka.ms/... Violet Typhoon =~ APT31 & Judgement Panda Linen Typhoon =~ APT27 & Emissary Panda & Red Phoenix & Lucky Mouse (it also lists Wekby2 - which feels like a blast from the past 🙃)
-
@msftsecresponse
@msftsecresponse
on x
Microsoft has released security updates for all supported on-premises SharePoint Server versions. Cloud-hosted SharePoint is not affected. We strongly urge customers to apply these updates immediately to protect against active exploitation. Our latest blog also shares insights
-
@therecord_media
@therecord_media
on x
Microsoft said previously known Chinese nation-state operations that it tracks as Linen Typhoon and Violet Typhoon — as well as a third, less-known group — were among those exploiting serious bugs in SharePoint server software https://therecord.media/...
-
@gi7w0rm
@gi7w0rm
on x
That SharePoint thing is so bad. Attackers don't deploy a webshell or smth. They leak a core sensitive key of the system allowing to validly sign certain request. Even if you patch the instance, attacks still can use the keys in the future. Only rotating the Keys will fix that...…
-
@ericgeller
Eric Geller
on x
At least 3 Chinese hacker groups, two of them linked to Beijing, are exploiting the recently disclosed SharePoint vulnerabilities, according to Microsoft. Google confirms “a China-nexus threat actor” conducted early exploitation. https://www.microsoft.com/... https://www.linkedi…