Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies

Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies

First seen 12 Aug 2026, 16:15 UTC cyberscoop.comwww.cnbc.com 80% similarity 80.8

Article Content

Browse articles
ThreatCluster

A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as Linen Typhoon, Violet Typhoon, and Storm-2603, began with the deployment of Warlock ransomware on July 18. The vulnerabilities, CVE-2025-53770 and CVE-2025-53771, are critical, allowing remote code execution and security bypass. Microsoft released patches for affected SharePoint versions on July 22, but attackers are modifying policy settings to maintain access post-patch. The Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its catalog of exploited vulnerabilities. The situation remains fluid as more organizations confirm varying levels of compromise.

Key Points: • Over 400 organizations, including US agencies, have been compromised by SharePoint attacks. • The attacks exploit critical zero-day vulnerabilities CVE-2025-53770 and CVE-2025-53771. • Chinese state-affiliated groups, including Linen Typhoon and Storm-2603, are behind the attacks.

ThreatCluster AI How this analysis works

Timeline

2025-07-07
Chinese hacking groups begin exploiting vulnerabilities
Linen Typhoon and Violet Typhoon start targeting SharePoint vulnerabilities, leading to widespread attacks.
CNBC
2025-07-08
CVE-2025-49706 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-07-08
CVE-2025-49704 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-07-18
Warlock ransomware deployed
Storm-2603 initiates attacks by deploying Warlock ransomware on compromised SharePoint servers.
CyberScoop
2025-07-20
CVE-2025-53770 and CVE-2025-53771 published
Microsoft publishes critical vulnerabilities allowing remote code execution and security bypass.
CyberScoop
2025-07-22
CISA adds vulnerabilities to exploited catalog
CISA acknowledges active exploitation of CVE-2025-53770 and CVE-2025-49704, urging immediate action.
CyberScoop
2025-09-18
CVE-2025-47906 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-24
CVE-2025-47904 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
Ongoing impact assessment
Microsoft continues to assess the scope of the attack as more victims report compromises.
CyberScoop

Community

Browse all →