The Wiretap: Chinese Hackers Exploit Microsoft Sharepoint 0-Day, Google Warns
CHINA, JUL 22 – Microsoft identified Beijing-backed hacking groups exploiting a critical vulnerability in on-premises SharePoint servers to steal data from governments and businesses worldwide, with over 10,000 servers at risk.
- In a global campaign, hackers exploited a Microsoft SharePoint zero-day vulnerability, breaching organizations worldwide and stealing sensitive data, officials and cybersecurity researchers say.
- Security researchers first identified ToolShell flaws in May, leaving on-premises SharePoint servers unpatched and vulnerable to exploitation.
- Hundreds of attack attempts unfolded across 160 environments since July 18, 2025, CrowdStrike observed, according to the cybersecurity firm.
- Following the breaches, attackers exfiltrated usernames, passwords, hash codes and tokens, exposing the breach's severity.
- Microsoft assesses high confidence that threat actors will continue exploiting these vulnerabilities, with CISA still assessing the scope of the attacks, according to sources.
48 Articles
48 Articles
They increase the victims of the large-scale hacker attack by exploiting a vulnerability of SharePoint, to the web platform for collaboration, content management and the creation of Microsoft's corporate websites. The US group has attributed the action also to Chinese actors. Accused that it outraged Beijing. According to estimates of the Dutch security company Eye Security, hackers have violated the data of about 400 government agencies, compan…
A vulnerability in Microsoft opens the door to cyber-attacks. The US software manufacturer is tracking a trail to China. However, Beijing remains word-karg in the matter.
According to software manufacturer Microsoft, the latest cyber attacks on numerous companies and authorities worldwide have been controlled from China.
Coverage Details
Bias Distribution
- 46% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium