Microsoft, SharePoint
Digest more
Reports suggest that Chinese?linked hackers exploited two unpatched flaws in on?premises SharePoint to breach around 100 organizations in a single weekend. Microsoft (MFT) rushed out fixes and urged everyone to update right away.
Hours after Microsoft revealed hacking groups affiliated with the Chinese government have been exploiting a flaw in its SharePoint software, Bloomberg News reports that the National Nuclear Security Administration has also been breached in the attacks.
In a blog post Tuesday, Microsoft said it observed hackers attempting to “gain initial access to target organizations.” According to Microsoft, those involved included hacking groups called Linen Typhoon and Violet Typhoon—which Microsoft said are linked to the Chinese government—and China-based group Storm-2603.
To secure the endpoints, Microsoft recommends applying the July 2025 security updates immediately, as well as enabling Antimalware Scan Interface (AMSI) for SharePoint and making sure Defender Antivirus is deployed.
Microsoft released an emergency security patch on Sunday to “mitigate active attacks targeting on-premises servers.”