logo

Chinese nation-state groups exploiting SharePoint vulnerability, Microsoft confirms

ID: 91a60558-d3f1-5471-b0bf-2e411ec153aa

STIX ID: report--91a60558-d3f1-5471-b0bf-2e411ec153aa

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-07-22

Date Updated: 2026-05-01

...
...

Microsoft warned that Chinese-linked nation-state actors (Linen Typhoon/APT27, Violet Typhoon/APT31 and a third group) have been actively exploiting multiple on‑premises SharePoint vulnerabilities (notably CVE-2025-49706 and CVE-2025-49704 and related bypasses CVE-2025-53770/53771) since early July, impacting over 100 organizations, enabling data exfiltration and theft of cryptographic keys; CISA added the flaws to its Known Exploited Vulnerabilities catalog and Microsoft released patches, though attackers have been observed bypassing fixes and maintaining long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.