www.cnbc.com
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as Linen Typhoon, Violet Typhoon, and Storm-2603, began with the deployment of Warlock ransomware on July 18. The vulnerabilities, CVE-2025-53770 and CVE-2025-53771, are critical, allowing remote code execution and security bypass. Microsoft released patches for affected SharePoint versions on July 22, but attackers are modifying policy settings to maintain access post-patch. The Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its catalog of exploited vulnerabilities. The situation remains fluid as more organizations confirm varying levels of compromise.
Key Points: • Over 400 organizations, including US agencies, have been compromised by SharePoint attacks. • The attacks exploit critical zero-day vulnerabilities CVE-2025-53770 and CVE-2025-53771. • Chinese state-affiliated groups, including Linen Typhoon and Storm-2603, are behind the attacks.