{"id":5663,"date":"2025-07-26T10:03:08","date_gmt":"2025-07-26T10:03:08","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/26\/microsoft-probes-leak-in-early-alert-system-as-chinese-hackers-exploit-sharepoint-vulnerabilities\/"},"modified":"2025-07-26T10:03:08","modified_gmt":"2025-07-26T10:03:08","slug":"microsoft-probes-leak-in-early-alert-system-as-chinese-hackers-exploit-sharepoint-vulnerabilities","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/26\/microsoft-probes-leak-in-early-alert-system-as-chinese-hackers-exploit-sharepoint-vulnerabilities\/","title":{"rendered":"Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities"},"content":{"rendered":"<p>    Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft Corp. is investigating whether a leak from its Microsoft Active Protections Program (MAPP) enabled Chinese state-sponsored hackers to exploit critical SharePoint vulnerabilities before patches were fully deployed, according to a Bloomberg report.<\/p>\n<p>The investigation comes as cyber espionage attacks have compromised more than 400 organizations worldwide, including the U.S. National Nuclear Security Administration.<\/p>\n<p>The timing of the attacks has raised significant red flags among cybersecurity experts. Vietnamese researcher Dinh Ho Anh Khoa first demonstrated the SharePoint vulnerabilities in May at the Pwn2Own cybersecurity conference in Berlin, earning $100,000 for his discovery.<\/p>\n<p>Microsoft issued initial patches in July, but MAPP partners were notified of the vulnerabilities on June 24, July 3, and July 7.<\/p>\n<p>Crucially, Microsoft first observed exploit attempts on July 7 \u2013 the same day as the final MAPP notification wave. \u201cThe likeliest scenario is that someone in the MAPP program used that information to create the exploits,\u201d said Dustin Childs, head of threat awareness at Trend Micro\u2019s Zero Day Initiative, whose company is a MAPP member.<\/p>\n<p>The sophisticated attack chain, dubbed \u201c<a href=\"https:\/\/cybersecuritynews.com\/sharepoint-0-day-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">ToolShell<\/a>\u201d by researchers, allows hackers to bypass authentication controls and execute malicious code on SharePoint servers. What makes this vulnerability particularly dangerous is that attackers can steal cryptographic machine keys, enabling them to maintain persistent access even after systems are patched.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Widespread Global Impact<\/strong><\/h2>\n<p>The cyberattack campaign has affected organizations across multiple sectors, with Microsoft attributing the breaches to three Chinese hacking groups: Linen Typhoon, <a href=\"https:\/\/cybersecuritynews.com\/sharepoint-0-day-ransomware-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Violet Typhoon<\/a>, and Storm-2603. <\/p>\n<p>The National Nuclear Security Administration, responsible for designing and maintaining America\u2019s nuclear weapons stockpile, was among the <a href=\"https:\/\/cybersecuritynews.com\/us-nuclear-weapons-agency-breached\/\" target=\"_blank\" rel=\"noreferrer noopener\">high-profile victims<\/a>, though officials say no classified information was compromised.<\/p>\n<p>\u201cOn Friday, July 18th, the exploitation of a Microsoft SharePoint zero-day vulnerability began affecting the Department of Energy, including the NNSA,\u201d a Department of Energy spokesperson confirmed. The agency said it was \u201cminimally impacted\u201d due to its widespread use of Microsoft\u2019s cloud services.<\/p>\n<p>Eye Security, the cybersecurity firm that first detected the attacks, reported more than 400 systems actively compromised across four confirmed waves of exploitation. Victims span government agencies, educational institutions, energy companies, and private corporations from North America to Europe and Asia.<\/p>\n<p>This wouldn\u2019t be the first time the MAPP program has been compromised. In 2012, Microsoft expelled Chinese firm Hangzhou DPtech Technologies Co. for violating its non-disclosure agreement after the company leaked proof-of-concept code for a Windows vulnerability. More recently, Qihoo 360 Technology Co. was removed from the program after being placed on the U.S. Entity List.<\/p>\n<p>At least a dozen Chinese companies currently participate in the 17-year-old MAPP program, which provides cybersecurity vendors with advance notice of vulnerabilities \u2013 typically 24 hours before public disclosure, with some trusted partners receiving information up to five days earlier, <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-07-25\/microsoft-sharepoint-hack-probe-on-whether-chinese-hackers-found-flaw-via-alert\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">according to<\/a> Bloomberg.<\/p>\n<p>\u201cAs part of our standard process, we\u2019ll review this incident, find areas to improve, and apply those improvements broadly,\u201d a Microsoft spokesperson said, emphasizing that partner programs remain \u201can important part of the company\u2019s security response.\u201d<\/p>\n<p>The Chinese Embassy in Washington has denied involvement, with Foreign Ministry spokesman Guo Jiakun stating that \u201cChina opposes and fights hacking activities in accordance with the law\u201d while opposing \u201csmears and attacks against China under the excuse of cybersecurity issues.\u201d<\/p>\n<p>The investigation highlights the delicate balance Microsoft faces in sharing vulnerability information with security partners while preventing malicious actors from exploiting advanced knowledge to accelerate attacks. Any confirmed leak would deal a significant blow to the MAPP program\u2019s credibility and effectiveness.<\/p>\n<p>As the probe continues, cybersecurity experts warn that the rapid weaponization of these <a href=\"https:\/\/cybersecuritynews.com\/defending-against-owasp-top-10-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerabilities<\/a> \u2013 from discovery to mass exploitation in just over two months \u2013 demonstrates the evolving sophistication and speed of modern cyber threats.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-&gt; <strong><a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jul&amp;utm_medium=article&amp;utm_campaign=freemium-exclusive&amp;utm_content=plans1&amp;utm_term=220725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-early-alert-sharepoint-vulnerabilities\/\">Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-early-alert-sharepoint-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Probes Leak in Early Alert System as Chinese Hackers Exploit SharePoint Vulnerabilities Microsoft Corp. is investigating whether a leak from its Microsoft Active Protections Program (MAPP) enabled Chinese state-sponsored hackers to exploit critical SharePoint vulnerabilities before patches were fully deployed, according to a Bloomberg report. The investigation comes as cyber espionage attacks have compromised [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63],"tags":[130],"class_list":["post-5663","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5663"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5663"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5663\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5663"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5663"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5663"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}