3 China Nation-State Actors Target SharePoint Bugs
ID: 8a19f7fc-9032-526d-9aeb-96f1a85b41f2
STIX ID: report--8a19f7fc-9032-526d-9aeb-96f1a85b41f2
Feed Name: Dark Reading
Threat Score
Microsoft and security researchers observed China-linked APTs (Linen Typhoon, Violet Typhoon, Storm-2603) exploiting multiple SharePoint zero-days (CVE-2025-49706, CVE-2025-49704 and later CVE-2025-53770/53771) via an attack chain dubbed "ToolShell" to deploy PowerShell-based backdoors, webshells and fileless malware and to exfiltrate keys; vendors advise immediate patching, credential/machine-key rotation, and hunting for provided IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
