6 Sources
[1]
Microsoft fixes two SharePoint zero-days under attack, but one is still unresolved - how to patch
Microsoft has patched two critical zero-day SharePoint security flaws that have already been exploited by hackers to attack vulnerable organizations. Responding to the exploits, the software giant has issued fixes for SharePoint Server Subscription Edition and SharePoint Server 2019, but is still
[2]
Microsoft fixes SharePoint zero-day exploits used in cyberattacks and ransomware - how to patch them
Microsoft has patched three critical zero-day SharePoint security flaws that hackers have already exploited to attack more vulnerable organizations. Responding to the exploits, the software giant initially issued fixes just for SharePoint Server Subscription Edition and SharePoint Server 2019, and
[3]
Microsoft fixes three SharePoint zero-day exploits used in cyberattacks and ransomware - how to patch them
Microsoft has patched three critical zero-day SharePoint security flaws that hackers have already exploited to attack more vulnerable organizations. Responding to the exploits, the software giant initially issued fixes just for SharePoint Server Subscription Edition and SharePoint Server 2019, and
[4]
SharePoint targeted by Chinese 'threat actor' hackers, says Microsoft
Security vulnerabilities exploited in servers hosting document-sharing software used by many large businesses Microsoft says Chinese "threat actors", including state-sponsored hackers, have exploited security vulnerabilities in its SharePoint document-sharing software servers and are targeting the
[5]
Microsoft Warns Of Active Exploits Targeting SharePoint Vulnerabilities - Microsoft (NASDAQ:MSFT)
Tim Melvin's system has spotted 10X winners like NVIDIA and Matador -- see his next 6 picks and the options strategies to multiply gains at a free July 23 event. Register Here. Microsoft Corp MSFT has issued a critical warning regarding ongoing attacks on on-premises SharePoint servers, urging
[6]
Microsoft claims China-backed hackers hit SharePoint systems
Microsoft has released comprehensive security updates for all supported versions of SharePoint Server. Microsoft has claimed that several China-backed hacker groups are actively targeting on-premises SharePoint servers. In a blog post, the tech giant confirmed that attackers are exploiting two
Share
Copy Link
Microsoft has released patches for critical zero-day vulnerabilities in SharePoint that were actively exploited by Chinese state-sponsored hackers, affecting government agencies and organizations worldwide.
Microsoft has recently patched critical zero-day vulnerabilities in its SharePoint server software that were actively exploited by Chinese state-sponsored hackers
1
. The vulnerabilities, designated as CVE-2025-53771 and CVE-2025-53770, affect only on-premises versions of SharePoint, leaving cloud-based SharePoint Online unaffected2
.
Source: ZDNet
CVE-2025-53771 is a SharePoint Server spoofing vulnerability, allowing attackers to impersonate trusted users or resources. CVE-2025-53770, rated as critical, is a remote code execution vulnerability that enables hackers to run code remotely in a SharePoint environment
2
. Together, these flaws allow cybercriminals to install malicious programs and compromise SharePoint environments.The vulnerabilities have been exploited to attack various organizations, including US federal and state agencies, universities, and energy companies
3
. Alarmingly, even the US National Nuclear Security Administration was breached4
. Microsoft has attributed the attacks to three Chinese nation-state actors: Linen Typhoon, Violet Typhoon, and Storm-26031
.In a concerning development, Microsoft observed Storm-2603 deploying Warlock ransomware using these vulnerabilities. This ransomware strain not only encrypts data but also steals it, enabling double-extortion tactics
3
.
Source: Digit
Microsoft initially attempted to fix the vulnerabilities with its July 8 Patch Tuesday updates. However, these patches proved insufficient, allowing hackers to bypass them
2
. The company has since released more robust protections, urging all users of on-premises SharePoint systems to install them immediately5
.Related Stories
This incident occurs against a backdrop of increasing geopolitical tensions between the US and China, particularly in the tech sector. Reports suggest that major companies like Amazon and McKinsey are scaling back AI-related operations in China, while US officials intensify scrutiny of US companies working on AI in China
4
.
Source: ZDNet
Microsoft strongly advises all organizations using on-premises SharePoint servers to apply the latest security updates without delay. The company warns that delayed patching could leave systems vulnerable to expanding campaigns
5
. Additionally, Microsoft has published indicators of compromise and threat-hunting queries to assist defenders in identifying malicious activities3
.Summarized by
Navi
[1]
[2]
09 Jul 2026•Technology

10 Jun 2026•Technology

09 Sept 2026•Technology

1
Technology

2
Policy and Regulation

3
Policy and Regulation
