/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says it “has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting” the SharePoint zero-day vulnerabilities

He said not as vulnerable as on-prem SharePoint right now.  —  #nerdromancewithpits @wylienewmark : back in the day, attribution of widespread exploitation of a vulnerability in a ubiquitous piece of software used *kinda* up in the air.  now, a guess of “China” has roughly a 60% chance of being correct. Mastodon: Sergiu Gatlan / @serghei@mastodon.social : Microsoft links the SharePoint ToolShell attacks to three Chinese hacking groups:  — Chinese nation-state threat groups Linen Typhoon and Violet Typhoon  — China-based threat actor tracked as Storm-2603  —  https://www.bleepingcomputer.com/ ... X: @msftsecintel : Microsoft is sharing details from ongoing investigations of threat actors exploiting vulnerabilities targeting on-premises SharePoint servers. Linen Typhoon, Violet Typhoon, and Storm-2603 have been observed exploiting the vulnerabilities: https://www.microsoft.com/... Christopher Glyer / @cglyer : MSTIC blog on Sharepoint exploitation At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7: Linen Typhoon Violet Typhoon Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown) https://www.microsoft.com/... Christopher Glyer / @cglyer : You can find Microsoft's mapping of the most common threat actors at https://aka.ms/... Violet Typhoon =~ APT31 & Judgement Panda Linen Typhoon =~ APT27 & Emissary Panda & Red Phoenix & Lucky Mouse (it also lists Wekby2 - which feels like a blast from the past 🙃) @msftsecresponse : Microsoft has released security updates for all supported on-premises SharePoint Server versions. Cloud-hosted SharePoint is not affected. We strongly urge customers to apply these updates immediately to protect against active exploitation. Our latest blog also shares insights @therecord_media : Microsoft said previously known Chinese nation-state operations that it tracks as Linen Typhoon and Violet Typhoon — as well as a third, less-known group — were among those exploiting serious bugs in SharePoint server software https://therecord.media/... @gi7w0rm : That SharePoint thing is so bad. Attackers don't deploy a webshell or smth. They leak a core sensitive key of the system allowing to validly sign certain request. Even if you patch the instance, attacks still can use the keys in the future. Only rotating the Keys will fix that... [image] Eric Geller / @ericgeller : At least 3 Chinese hacker groups, two of them linked to Beijing, are exploiting the recently disclosed SharePoint vulnerabilities, according to Microsoft. Google confirms “a China-nexus threat actor” conducted early exploitation. https://www.microsoft.com/... https://www.linkedin.com/... [image]

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Microsoft had already issued updates for supported on-premises versions after global exploitation of a SharePoint remote-code-execution flaw, while stating that cloud-hosted SharePoint was unaffected. This report adds named threat clusters to that incident response.

The attribution aligns with researchers’ earlier assessment of China-linked involvement and gives defenders more specific intelligence for investigation and threat hunting.

First-order effects

  • Organizations running on-premises SharePoint must treat the vulnerabilities as an active nation-state intrusion risk and prioritize Microsoft’s available updates and incident review.
  • Microsoft’s public attribution associates the exploitation with Linen Typhoon, Violet Typhoon, and Storm-2603, giving security teams actor-specific context alongside the technical indicators.

Second-order effects

  • Enterprise security teams and managed defenders will likely expand SharePoint-focused monitoring and hunt for activity associated with the named groups, not merely verify patch installation.
  • The contrast between affected on-premises deployments and unaffected cloud-hosted SharePoint sharpens the operational-security trade-off customers face in maintaining legacy self-managed collaboration infrastructure.

Third-order effects

  • If repeated exploitation of on-premises collaboration software persists, security posture will increasingly be shaped by whether organizations can retire or isolate internet-exposed self-managed systems—not only by how quickly they patch.
  • More public, actor-level attribution may make vendor incident communications a more important input to enterprise response planning, though attribution alone does not establish the attackers’ objectives.

The trend: This is one instance of critical enterprise software becoming a recurring state-linked access point, increasing pressure to reduce exposure in self-managed infrastructure.

Discussion

  • @aelkus @aelkus on bluesky
    there are people here in DC who have entire businesses built around classified sharepoint management
  • @pits666 @pits666 on bluesky
    She said that she felt vulnerable.  —  He said not as vulnerable as on-prem SharePoint right now.  —  #nerdromancewithpits
  • @wylienewmark @wylienewmark on bluesky
    back in the day, attribution of widespread exploitation of a vulnerability in a ubiquitous piece of software used *kinda* up in the air.  now, a guess of “China” has roughly a 60% chance of being correct.
  • @serghei@mastodon.social Sergiu Gatlan on mastodon
    Microsoft links the SharePoint ToolShell attacks to three Chinese hacking groups:  — Chinese nation-state threat groups Linen Typhoon and Violet Typhoon  — China-based threat actor tracked as Storm-2603  —  https://www.bleepingcomputer.com/ ...
  • @msftsecintel @msftsecintel on x
    Microsoft is sharing details from ongoing investigations of threat actors exploiting vulnerabilities targeting on-premises SharePoint servers. Linen Typhoon, Violet Typhoon, and Storm-2603 have been observed exploiting the vulnerabilities: https://www.microsoft.com/...
  • @cglyer Christopher Glyer on x
    MSTIC blog on Sharepoint exploitation At least 3 actors exploiting CVE-2025-49706 & CVE-2025-49704 as early as July 7: Linen Typhoon Violet Typhoon Storm-2603 (CN-based actor deployed Warlock & Lockbit ransomware in past - current motivation unknown) https://www.microsoft.com/...
  • @cglyer Christopher Glyer on x
    You can find Microsoft's mapping of the most common threat actors at https://aka.ms/... Violet Typhoon =~ APT31 & Judgement Panda Linen Typhoon =~ APT27 & Emissary Panda & Red Phoenix & Lucky Mouse (it also lists Wekby2 - which feels like a blast from the past 🙃)
  • @msftsecresponse @msftsecresponse on x
    Microsoft has released security updates for all supported on-premises SharePoint Server versions. Cloud-hosted SharePoint is not affected. We strongly urge customers to apply these updates immediately to protect against active exploitation. Our latest blog also shares insights
  • @therecord_media @therecord_media on x
    Microsoft said previously known Chinese nation-state operations that it tracks as Linen Typhoon and Violet Typhoon — as well as a third, less-known group — were among those exploiting serious bugs in SharePoint server software https://therecord.media/...
  • @gi7w0rm @gi7w0rm on x
    That SharePoint thing is so bad. Attackers don't deploy a webshell or smth. They leak a core sensitive key of the system allowing to validly sign certain request. Even if you patch the instance, attacks still can use the keys in the future. Only rotating the Keys will fix that...…
  • @ericgeller Eric Geller on x
    At least 3 Chinese hacker groups, two of them linked to Beijing, are exploiting the recently disclosed SharePoint vulnerabilities, according to Microsoft. Google confirms “a China-nexus threat actor” conducted early exploitation. https://www.microsoft.com/... https://www.linkedi…