logo

China says US spies exploited Microsoft Exchange zero-day to steal military info

ID: e4c86f43-339a-53b4-b279-1d67e9cde7ad

STIX ID: report--e4c86f43-339a-53b4-b279-1d67e9cde7ad

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-08-01

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

CNCERT/CC alleges that US intelligence exploited a Microsoft Exchange zero-day (July 2022–July 2023) to breach a major Chinese military enterprise—compromising its domain controller, controlling over 50 internal devices, and stealing emails containing defense-related designs—and that a separate July–November 2024 campaign used SQL injection and backdoors to compromise 300+ devices in communications and satellite internet sectors; the bulletin cites techniques such as WebSocket-over-SSH tunnels, covert channels, and use of international IP addresses to stage the intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.