Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025
    Facebook X (Twitter) Instagram
    Trending
    • My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why
    • You can now buy the OnePlus 15 in the US and score free earbuds if you hurry
    • Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455
    • Android might finally stop making you tap twice for Wi-Fi
    • Today’s NYT Mini Crossword Answers for Dec. 22
    • Waymo’s robotaxis didn’t know what to do when a city’s traffic lights failed
    • Today’s NYT Wordle Hints, Answer and Help for Dec. 22 #1647
    • You Asked: OLED Sunlight, VHS on 4K TVs, and HDMI Control Issues
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»Gaming»Microsoft confirms SharePoint vulnerabilities have been exploited by suspected Chinese hackers, as reports indicate the US Nuclear Security Administration may have been among those compromised
    Gaming

    Microsoft confirms SharePoint vulnerabilities have been exploited by suspected Chinese hackers, as reports indicate the US Nuclear Security Administration may have been among those compromised

    techupdateadminBy techupdateadminJuly 23, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A logo marking the edge of the Microsoft corporate campus in Redmond, Washington.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Following on from Microsoft’s warning earlier this week that “active attacks” were targeting its SharePoint Server customers through a known exploit, the company has now released a blog post revealing more details about the breach. According to MS, on-premises SharePoint servers were determined to have been attacked by three allegedly Chinese nation-state actors, Linen Typhoon, Violet Typhoon, and Storm-2603, via a known spoofing vulnerability and a remote code execution vulnerability.

    Reuters reported on Monday that, according to Vaisha Bernard, chief hacker at Eye Security, around 100 organisations were compromised as of the weekend. The Shadowserver Foundation said that most of those affected were in the United States and Germany, and the victims included government organisations.

    Bloomberg has since reported that “a person with knowledge of the matter” confirmed that hackers used the SharePoint flaws to break into the US National Nuclear Security Administration, among others, although no sensitive or classified information was compromised. The US federal agency is responsible for managing and maintaining the US nuclear weapons stockpile, along with providing nuclear propulsion plants for US submarines and promoting international nuclear safety.


    Related Articles

    A security patch released earlier this month appears to have failed to fix the vulnerabilities, which were said to be first identified in May at a hacking competition in Berlin.

    Microsoft says that only on-prem servers were affected by the hack, and that the vulnerabilities in question (CVE-2025-49706 and CVE-2025-49704 respectively) have since been successfully patched out in all supported versions of SharePoint Server. MS advises that “customers should apply these updates immediately” to ensure they are protected.

    (Image credit: quantic69 via Getty Images)

    “With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems,” the company continues.

    “Customers should also integrate and enable Antimalware Scan Interface (AMSI) and Microsoft Defender Antivirus (or equivalent solutions) for all on-premises SharePoint deployments and configure AMSI to enable Full Mode. Customers should also rotate SharePoint server ASP.NET machine keys, restart Internet Information Services (IIS), and deploy Microsoft Defender for Endpoint or equivalent solutions.”

    Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.

    I’d imagine all that might be quite the headache for sysadmins working with SharePoint servers, but at this point it’s probably better to be safe than sorry. The hacking groups identified are said to have prior form, with Linen Typhoon and Violet Typhoon supposedly responsible for a litany of digital crimes, including stealing intellectual property, enacting government and military espionage, and exploiting digital weaknesses to install web shells.

    A stylised photograph of a person acting as a hacker, break into servers and infecting them with a virus, as show by computer monitors displaying green text and codes Their System with a Virus

    (Image credit: Witthaya Prasongsin via Getty Images)

    Storm-2603, meanwhile, appears to be more mysterious. MS says that it has assessed the group with “medium confidence” to be a China-based threat actor, although it’s been unable to link it directly with the hacking groups above. Reuters also reports that the Chinese embassy in Washington has already released a statement confirming that China is against all forms of cyberattacks, and that it firmly opposes “smearing others without solid evidence.”

    “We hope that relevant parties will adopt a professional and responsible attitude when characterizing cyber incidents, basing their conclusions on sufficient evidence rather than unfounded speculation and accusations,” the embassy said.

    In 2023, Microsoft hit the headlines over a high-profile US government email hack, also attributed to Chinese hacking groups. The federal Cyber Safety Review board later released a report on the incident, identifying a “cascade of Microsoft’s avoidable errors that allowed this intrusion to succeed.” Given that Microsoft’s server infrastructure seems so innately tied to sensitive US government operations at this point, and the potential severity of this particular breach, it remains to be seen whether the US government will order a similar review again.

    HP OMEN 35L

    Best gaming PC 2025

    All our current recommendations
    Administration among Chinese compromised Confirms exploited Hackers Microsoft Nuclear reports security SharePoint suspected vulnerabilities
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleItel Super Guru 4G Max Feature Phone Launched in India With 3-Inch Display, Built-In AI Voice Assistant
    Next Article Sony’s gamer-friendly X90L TV is on sale for a new low price
    techupdateadmin
    • Website

    Related Posts

    Gadgets

    Google confirms Gemini will fully replace Assistant on phones in 2026

    December 20, 2025
    Mobile

    Brits are now trauma-dumping on AI, government confirms

    December 20, 2025
    Gadgets

    Microsoft makes theming your Windows 11 PC as easy as phones, but not as much fun

    December 15, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    NYT Strands hints and answers for Monday, August 11 (game #526)

    August 11, 202545 Views

    These 2 Cities Are Pushing Back on Data Centers. Here’s What They’re Worried About

    September 13, 202542 Views

    Today’s NYT Connections: Sports Edition Hints, Answers for Sept. 4 #346

    September 4, 202540 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    My Health Anxiety Means I Won’t Use Apple’s or Samsung’s Smartwatches. Here’s Why

    December 22, 2025

    You can now buy the OnePlus 15 in the US and score free earbuds if you hurry

    December 22, 2025

    Today’s NYT Connections: Sports Edition Hints, Answers for Dec. 22 #455

    December 22, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2026 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.