logo

Blame a leak for Microsoft SharePoint attacks, researcher insists

ID: c4012381-7575-594c-8f9e-956bfcef09f8

STIX ID: report--c4012381-7575-594c-8f9e-956bfcef09f8

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-07-26

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers reported mass exploitation of recently disclosed SharePoint vulnerabilities (CVE-2025-49704 — unauthenticated RCE — and CVE-2025-49706 — spoofing) that bypassed initial Microsoft patches; more than 400 organizations were compromised by Chinese state-linked groups (Linen Typhoon, Violet Typhoon) and the Storm-2603 ransomware gang, and investigators suspect a leak from Pwn2Own/MAPP disclosures or independent reproduction potentially aided by large language models.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.