logo

Three hacking groups, two vulnerabilities and all eyes on China

ID: fe7424c1-7593-5f29-a49e-8533af85c4b3

STIX ID: report--fe7424c1-7593-5f29-a49e-8533af85c4b3

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-12-08

Date Updated: 2026-05-01

...
...

**Executive summary:** Multiple China-linked threat clusters (Linen Typhoon/APT27, Violet Typhoon/APT31 and Storm-2603) exploited Microsoft SharePoint vulnerabilities (notably CVE-2025-49704, CVE-2025-49706 and follow-on bypasses) in the ToolShell campaign to gain access to hundreds of government and enterprise on‑premise SharePoint servers, prompting urgent patches and concerns about coordinated or rapidly shared exploit capabilities and mixed espionage/financial motives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.