China News
CYBER WARS
Chinese state hackers targeting Microsoft customers
Chinese state hackers targeting Microsoft customers
by AFP Staff Writers
San Francisco, United States (AFP) July 22, 2025

Chinese state-sponsored hackers are actively exploiting critical security vulnerabilities in users of Microsoft's popular SharePoint servers to steal sensitive data and deploy malicious code, the US tech giant warned Tuesday.

Microsoft said it has observed three threat groups -- dubbed Linen Typhoon, Violet Typhoon, and Storm-2603 -- targeting internet-facing SharePoint servers using two newly disclosed vulnerabilities that allow attackers to bypass authentication and execute remote code.

SharePoint Server is Microsoft's collaboration and document management platform designed for businesses and organizations.

Many large organizations use SharePoint as their primary platform for internal collaboration and for storing documents, and is appreciated for working well with other Microsoft products like Office, Teams, and Outlook.

The attacks, which Microsoft said began as early as July 7, affect only on-premises SharePoint installations and do not impact the cloud-based SharePoint Online service, the company said in a security bulletin.

Microsoft warned that it "assesses with high confidence" that the threat actors will continue their assault against vulnerable systems where companies haven't taken the necessary precautions.

The vulnerabilities allow attackers to spoof authentication credentials and execute malicious code remotely on vulnerable servers.

Microsoft has released comprehensive security updates to address the malware and urged customers to apply the patches immediately.

In their successful attacks, the Chinese hackers deployed malicious code that provides backdoor access to compromised systems. The attackers used these tools to steal machine encryption keys and maintain access to targeted networks.

Linen Typhoon, active since 2012, primarily focuses on intellectual property theft from government, defense, and human rights organizations.

Violet Typhoon, operating since 2015, conducts espionage against former government officials, NGOs, think tanks, and media organizations across the United States, Europe, and East Asia.

Storm-2603, which Microsoft assesses with "medium confidence" to be China-based, has previously deployed ransomware but its current objectives remain unclear.

Research from cybersecurity company Check Point said the campaign began on July 7 against a major Western government and that the attacks intensified dramatically around July 18.

Since then, researchers have confirmed dozens of compromise attempts primarily targeting organizations in North America and Western Europe, Check Point said in a blog post.

Related Links
Cyberwar - Internet Security News - Systems and Policy Issues

Subscribe Free To Our Daily Newsletters
Tweet

RELATED CONTENT
The following news reports may link to other Space Media Network websites.
CYBER WARS
Chinese-born engineer pleads guilty to stealing US trade secrets
Los Angeles, United States (AFP) July 21, 2025
A Chinese-born US researcher pleaded guilty on Monday to stealing trade secrets, including technology used to detect nuclear missile launches, the Justice Department said. Chenguang Gong, 59, of San Jose, California, was accused of transferring more than 3,600 files from the research and development company where he worked to his personal storage devices. Gong pleaded guilty in a central California district court on Monday to one count of theft of trade secrets and faces a maximum penalty of 10 ... read more

CYBER WARS
Six Chinese universities to launch new low altitude space major this fall

International deep space alliance launched in Hefei China

China launches international association to boost global access to deep space research

Chinese Long March Rockets Make International Debut at Paris Air Show

CYBER WARS
Xi says China, EU must deepen trust but bloc chief urges 'real solutions'

Trump announces 'massive' Japan trade deal

Tokyo's Nikkei leads Asian rally after Japan-US trade deal

US-China set to meet with extension of tariff pause on the cards

CYBER WARS
CYBER WARS
EU says China's links with Russia now 'determining factor' in ties

Europe hopes for 'no surprises' as US weighs force withdrawals

Georgia hosts NATO drills despite cooling ties with the West

Trump set to visit Scotland for trade talks, and some golf

CYBER WARS
Three drones detected in Japan nuclear plant

Joint KIT and EU Effort Aims to Advance Nuclear Safety and Scientific Expertise

Framatome to supply nuclear fuel for Barakah plant boosting UAE energy security

Framatome opens advanced additive manufacturing hub in France

CYBER WARS
Russia seeks to fine web users searching for content deemed 'extremist'

Risk highlighted as Chinese hackers hit Microsoft

China urges global consensus on balancing AI development, security

Chinese state hackers targeting Microsoft customers

CYBER WARS
Three drones detected in Japan nuclear plant

Joint KIT and EU Effort Aims to Advance Nuclear Safety and Scientific Expertise

Framatome to supply nuclear fuel for Barakah plant boosting UAE energy security

Framatome opens advanced additive manufacturing hub in France

CYBER WARS
Drone swarm explores turbulent airflows near wind turbines

Dogs on the trail of South Africa's endangered tortoises

UK ditches mega green energy supply project from Morocco

Trump admin ends halt on New York offshore wind project

Subscribe Free To Our Daily Newsletters




The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us.