Three hacking groups, two vulnerabilities and all eyes on China
ID: fe7424c1-7593-5f29-a49e-8533af85c4b3
STIX ID: report--fe7424c1-7593-5f29-a49e-8533af85c4b3
Feed Name: The Record from Recorded Future News
**Executive summary:** Multiple China-linked threat clusters (Linen Typhoon/APT27, Violet Typhoon/APT31 and Storm-2603) exploited Microsoft SharePoint vulnerabilities (notably CVE-2025-49704, CVE-2025-49706 and follow-on bypasses) in the ToolShell campaign to gain access to hundreds of government and enterprise on‑premise SharePoint servers, prompting urgent patches and concerns about coordinated or rapidly shared exploit capabilities and mixed espionage/financial motives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
