www.cnbc.com Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
Article Content
- •Over 400 organizations, including US agencies, have been compromised by SharePoint attacks.
- •The attacks exploit critical zero-day vulnerabilities CVE-2025-53770 and CVE-2025-53771.
- •Chinese state-affiliated groups, including Linen Typhoon and Storm-2603, are behind the attacks.
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as Linen Typhoon, Violet Typhoon, and Storm-2603, began with the deployment of Warlock ransomware on July 18. The vulnerabilities, CVE-2025-53770 and CVE-2025-53771, are critical, allowing remote code execution and security bypass. Microsoft released patches for affected SharePoint versions on July 22, but attackers are modifying policy settings to maintain access post-patch. The Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its catalog of exploited vulnerabilities. The situation remains fluid as more organizations confirm varying levels of compromise.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Warlock, Hafnium and California Independent System Operator in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Warlock Ransomware Targets Critical Infrastructure in Spanish and Portuguese Regions The Warlock ransomware group, tracked as Longlegs or Storm-2603, has targeted critical infrastructure in Portuguese- and Spanish-speaking countries, including a water utility, a telecommunications provider, a regional government body, and an university. Recent attacks exploited vulnerabilities in Microsoft SharePoint…
FBI Disrupts Chinese State-Sponsored Exploitation of Microsoft Exchange Vulnerabilities On April 13, 2021, the FBI executed a novel operation to remove malicious web shells from U.S.-based computers, attributed to the Chinese state-sponsored group Hafnium. These web shells exploited zero-day vulnerabilities in Microsoft Exchange servers, allowing unauthorized access and persistent malware deployment.…