BREAKINGON

Urgent Cybersecurity Alert: Chinese Hackers Target Microsoft SharePoint Zero-Day Flaw

7/22/2025
Security researchers reveal that Chinese hackers are exploiting a critical zero-day bug in Microsoft SharePoint, allowing them to steal sensitive data and plant malware. Companies are urged to patch their systems immediately to avoid compromise.
Urgent Cybersecurity Alert: Chinese Hackers Target Microsoft SharePoint Zero-Day Flaw
Chinese hackers are exploiting a zero-day vulnerability in Microsoft SharePoint, threatening sensitive corporate data. Urgent action is required to prevent breaches.

China-Backed Hackers Exploit Zero-Day Vulnerability in Microsoft SharePoint

Security researchers from Google and Microsoft have uncovered alarming evidence that hackers supported by China are actively exploiting a zero-day vulnerability in Microsoft SharePoint. This flaw, officially designated as CVE-2025-53770, was discovered just last weekend and has prompted a global scramble among companies to patch the security breach. The vulnerability allows malicious actors to steal sensitive private keys from self-hosted versions of SharePoint, a widely used software server for storing and sharing internal documents.

How the Vulnerability Works

Once exploited, this zero-day bug enables attackers to remotely install malware and gain unauthorized access to sensitive files and data stored within SharePoint. Furthermore, they can potentially infiltrate other systems connected to the same network, escalating the risk of data breaches across organizations. As the situation develops, companies are urged to prioritize the security of their SharePoint installations.

Involvement of China-Backed Hacking Groups

In a recent blog post, Microsoft reported that it has identified at least two well-known hacking groups with ties to China, dubbed “Linen Typhoon” and “Violet Typhoon”, as being actively involved in exploiting this zero-day vulnerability. Microsoft describes Linen Typhoon as primarily focused on intellectual property theft, whereas Violet Typhoon targets private information for espionage purposes. The company also referenced a third group, “Storm-2603,” which has less publicly available information but has been linked to previous ransomware attacks.

Timeline of Exploitation

Microsoft indicated that these hacking groups have been exploiting the zero-day vulnerability to compromise unprotected SharePoint servers since at least July 7. Charles Carmakal, the Chief Technology Officer at Google’s incident response unit Mandiant, confirmed in an email to TechCrunch that “at least one of the actors responsible” is a hacking group with connections to China, emphasizing that “multiple actors are now actively exploiting this vulnerability.”

Impact on Organizations

Dozens of organizations, including those in the government sector, have already fallen victim to these cyberattacks. The current bug is classified as a zero-day because Microsoft had insufficient time to issue a patch before it was exploited in the wild. Although Microsoft has since released security patches for all affected SharePoint versions, security experts caution that organizations running self-hosted versions should assume they have already been compromised.

China’s Response to Allegations

As the situation continues to unfold, a spokesperson for the Chinese Embassy in Washington D.C. has not responded to requests for comment. Historically, the Chinese government has denied allegations of conducting cyberattacks, although it has not explicitly refuted its involvement in this specific case.

As companies navigate this serious threat, vigilance and prompt action to apply security updates are essential in mitigating the risks associated with this zero-day vulnerability in Microsoft SharePoint.

Breakingon.com is an independent news platform that delivers the latest news, trends, and analyses quickly and objectively. We gather and present the most important developments from around the world and local sources with accuracy and reliability. Our goal is to provide our readers with factual, unbiased, and comprehensive news content, making information easily accessible. Stay informed with us!
© Copyright 2025 BreakingOn. All rights reserved.