Microsoft says it “has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting” the SharePoint zero-day vulnerabilities
He said not as vulnerable as on-prem SharePoint right now. — #nerdromancewithpits @wylienewmark : back in the day, attribution of widespread exploitation of a vulnerability in a ubiquitous piece of software used *kinda* up in the air. now, a guess of “China” has roughly a 60% chance of being correct. Mastodon: Sergiu Gatlan / @serghei@mastodon.social : Microsoft links the SharePoint ToolShell attacks to three Chinese hacking groups: — Chinese nation-state threat groups Linen Typhoon and Violet Typhoon — China-based threat actor tracked as Storm-2603 — https://www.bleepingcomputer.com/ ... X: @msftsecintel : Microsoft is sharing details from ongoing investigations of threat actors exploiting vulnerabilities targeting on-premises SharePoint servers. Linen Typhoon, Violet Typhoon, and Storm-2603 have been observed exploiting the vulnerabilities: https://www.microsoft.com/... Christopher Glyer / @cglyer : MSTIC blog on Sharepoint exploitation At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7: Linen Typhoon Violet Typhoon Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown) https://www.microsoft.com/... Christopher Glyer / @cglyer : You can find Microsoft's mapping of the most common threat actors at https://aka.ms/... Violet Typhoon =~ APT31 & Judgement Panda Linen Typhoon =~ APT27 & Emissary Panda & Red Phoenix & Lucky Mouse (it also lists Wekby2 - which feels like a blast from the past 🙃) @msftsecresponse : Microsoft has released security updates for all supported on-premises SharePoint Server versions. Cloud-hosted SharePoint is not affected. We strongly urge customers to apply these updates immediately to protect against active exploitation. Our latest blog also shares insights @therecord_media : Microsoft said previously known Chinese nation-state operations that it tracks as Linen Typhoon and Violet Typhoon — as well as a third, less-known group — were among those exploiting serious bugs in SharePoint server software https://therecord.media/... @gi7w0rm : That SharePoint thing is so bad. Attackers don't deploy a webshell or smth. They leak a core sensitive key of the system allowing to validly sign certain request. Even if you patch the instance, attacks still can use the keys in the future. Only rotating the Keys will fix that... [image] Eric Geller / @ericgeller : At least 3 Chinese hacker groups, two of them linked to Beijing, are exploiting the recently disclosed SharePoint vulnerabilities, according to Microsoft. Google confirms “a China-nexus threat actor” conducted early exploitation. https://www.microsoft.com/... https://www.linkedin.com/... [image]
Context & Ripple Effects
Microsoft had already issued updates for supported on-premises versions after global exploitation of a SharePoint remote-code-execution flaw, while stating that cloud-hosted SharePoint was unaffected. This report adds named threat clusters to that incident response.
The attribution aligns with researchers’ earlier assessment of China-linked involvement and gives defenders more specific intelligence for investigation and threat hunting.
First-order effects
- Organizations running on-premises SharePoint must treat the vulnerabilities as an active nation-state intrusion risk and prioritize Microsoft’s available updates and incident review.
- Microsoft’s public attribution associates the exploitation with Linen Typhoon, Violet Typhoon, and Storm-2603, giving security teams actor-specific context alongside the technical indicators.
Second-order effects
- Enterprise security teams and managed defenders will likely expand SharePoint-focused monitoring and hunt for activity associated with the named groups, not merely verify patch installation.
- The contrast between affected on-premises deployments and unaffected cloud-hosted SharePoint sharpens the operational-security trade-off customers face in maintaining legacy self-managed collaboration infrastructure.
Third-order effects
- If repeated exploitation of on-premises collaboration software persists, security posture will increasingly be shaped by whether organizations can retire or isolate internet-exposed self-managed systems—not only by how quickly they patch.
- More public, actor-level attribution may make vendor incident communications a more important input to enterprise response planning, though attribution alone does not establish the attackers’ objectives.
The trend: This is one instance of critical enterprise software becoming a recurring state-linked access point, increasing pressure to reduce exposure in self-managed infrastructure.