CISA Orders Urgent Patching After Chinese Hackers Exploit SharePoint Flaws in Live Attacks

Threat Score
75%
13 articles 100.0% Similarity 17 hours ago

Activity Timeline

Chinese cyber spies among those linked to SharePoi...
Computer Weekly IT Security
Jul 22
11:30
Microsoft confirms China link to SharePoint hacks...
Computer Weekly IT Security
Jul 22
12:12
Google, Microsoft say Chinese hackers are exploiti...
TechCrunch
Jul 22
14:45
Microsoft sees China-backed nation-state hackers a...
Cybersecurity Dive
Jul 22
15:22
Microsoft Links Ongoing SharePoint Exploits to Thr...
The Hacker News
Jul 22
15:45
Microsoft says Chinese hacking groups are behind S...
The Verge
Jul 22
16:13
Surprise, surprise: Chinese spies, IP stealers, ot...
The Register Security
Jul 22
16:40
Microsoft Reveals Chinese State Hackers Exploiting...
Hackread
Jul 22
17:02
Microsoft Traces On-Premises SharePoint Exploits t...
Data Breach Today UK
Jul 22
17:02
Microsoft knew of SharePoint security flaw in May,...
IT News Security
Jul 22
20:09
Microsoft servers hacked by Chinese groups, firm s...
BBC Technology
Jul 23
02:53
CISA Orders Urgent Patching After Chinese Hackers ...
The Hacker News
Primary Article
Jul 23
04:40
Chinese Hackers Exploit Active 0-Day Vulnerability...
GB Hackers
Jul 23
04:59
  • CISA has added two critical Microsoft SharePoint vulnerabilities, CVE-2025-49704 (RCE) and CVE-2025-49706 (spoofing), to its Known Exploited Vulnerabilities catalog due to active exploitation.
  • Chinese state-backed groups, including Linen Typhoon and Violet Typhoon, are exploiting these vulnerabilities in on-premises SharePoint servers, impacting over 100 organizations.
  • Microsoft has released urgent security updates for affected SharePoint versions, advising all on-premises users to apply these patches immediately to mitigate risks.
  • Proof-of-concept exploit code for these vulnerabilities is now publicly available, increasing the likelihood of further attacks by various threat actors.
  • Organizations must ensure their SharePoint servers are updated to the latest security versions to prevent unauthorized access and potential data breaches.

Chinese state-sponsored hackers are actively exploiting two critical vulnerabilities in Microsoft SharePoint servers (CVE-2025-49704 and CVE-2025-49706), affecting numerous organizations. These flaws allow unauthorized access and remote code execution, posing significant risks to businesses using on-premises installations. Microsoft has issued urgent security updates, and organizations must apply these patches immediately to safeguard their systems. Failure to do so could lead to data breaches and operational disruptions. Security teams should prioritize updating their SharePoint servers and monitor for any suspicious activity related to these vulnerabilities.

Save to Folder

Choose a folder to save this cluster: