Microsoft accuses China-backed nation state hackers of abusing the country's vulnerability disclosure requirements to discover and develop zero-day exploits
Jonathan Greig / The Record :
Context & Ripple Effects
This accusation reframes China's mandatory vulnerability reporting not as defensive policy but as a state-run exploit pipeline: bugs disclosed to Beijing become raw material for nation-state hacking teams. It is the earliest thread in a pattern the related coverage keeps returning to — Microsoft's own products as the recurring battleground.
The arc since then runs through Microsoft's contested disclosures around the 2023 US government email breach, where critics argued the company downplayed its own zero-days' role, to 2025, when Microsoft said the Linen Typhoon and Violet Typhoon groups were actively exploiting SharePoint zero-days. China has since answered in kind, alleging US exploitation of an old Exchange flaw at a defense firm — attribution claims flowing both directions across the same vendor stack.
First-order effects
- Chinese state-backed hacking groups gain a legally sanctioned discovery channel: vulnerabilities reported under domestic disclosure requirements can be developed into zero-days before vendors like Microsoft ever see them, putting Microsoft's enterprise and government customers directly in the blast radius.
Second-order effects
- Western governments and enterprises must weigh whether software sold into China carries a structurally higher zero-day risk, pressuring vendors on how they handle bugs found in jurisdictions with mandatory state disclosure — and fueling scrutiny of Microsoft's own patching record after the email-breach disclosures.
Third-order effects
- If disclosure mandates function as offensive-cyber infrastructure, vulnerability management splits along geopolitical lines: vendors face dueling state accusations — Microsoft blaming Chinese actors while China blames the US for Exchange exploits — and trust in cross-border bug handling erodes into bloc-by-bloc security postures.
The trend: National vulnerability-disclosure regimes are hardening into state exploit pipelines, with vendor attributions and counter-accusations becoming the routine public trace of that competition.