Chinese nation-state groups exploiting SharePoint vulnerability, Microsoft confirms
ID: 91a60558-d3f1-5471-b0bf-2e411ec153aa
STIX ID: report--91a60558-d3f1-5471-b0bf-2e411ec153aa
Feed Name: The Record from Recorded Future News
Microsoft warned that Chinese-linked nation-state actors (Linen Typhoon/APT27, Violet Typhoon/APT31 and a third group) have been actively exploiting multiple on‑premises SharePoint vulnerabilities (notably CVE-2025-49706 and CVE-2025-49704 and related bypasses CVE-2025-53770/53771) since early July, impacting over 100 organizations, enabling data exfiltration and theft of cryptographic keys; CISA added the flaws to its Known Exploited Vulnerabilities catalog and Microsoft released patches, though attackers have been observed bypassing fixes and maintaining long-term access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
