Surprise, surprise: Chinese spies, IP stealers, other miscreants attacking Microsoft SharePoint servers
ID: e6729b60-0d6e-5bbf-b203-d7ec01f8d9d7
STIX ID: report--e6729b60-0d6e-5bbf-b203-d7ec01f8d9d7
Feed Name: The Register (Security)
Microsoft reports active exploitation of chained SharePoint vulnerabilities (CVE-2025-53770 and CVE-2025-53771, linked to earlier CVEs) that enable authentication bypass and unauthenticated remote code execution; threat actors deploy web shells post-exploit. Attributed actors include Chinese-linked APTs Linen Typhoon (APT27), Violet Typhoon (APT31), and Storm-2603; fixes are available for SharePoint Server editions but public proofs-of-concept increase the likelihood of broader abuse, including ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
