Close Menu
TechUpdateAlert

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Best Mobile Phones Under Rs. 15,000 in India: From iQOO Z10X, Poco M7 Pro, Moto G85 and More

    August 9, 2025

    I watched Wednesday season 2, part 1 and the family drama makes it even better than its predecessor

    August 9, 2025

    Infinix Hot 60i 5G India Launch Confirmed; Will Debut With Dimensity 6400 SoC, 50-Megapixel Rear Camera

    August 9, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Best Mobile Phones Under Rs. 15,000 in India: From iQOO Z10X, Poco M7 Pro, Moto G85 and More
    • I watched Wednesday season 2, part 1 and the family drama makes it even better than its predecessor
    • Infinix Hot 60i 5G India Launch Confirmed; Will Debut With Dimensity 6400 SoC, 50-Megapixel Rear Camera
    • A Realme 15 Pro Game of Thrones Limited Edition is coming
    • Infinix GT 30 5G+ Launched in India With 64-Megapixel Rear Camera, GT Shoulder Triggers: Price, Specifications
    • Redmi 15 5G Price, Colour Options Listed on Website Ahead of Launch in Malaysia and Singapore
    • Today’s NYT Mini Crossword Answers for Aug. 9
    • iQOO TWS Air 3 Pro With Up to 50dB Adaptive ANC Launched Alongside iQOO 22.5W 10,000mAh Power Bank
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechUpdateAlertTechUpdateAlert
    • Home
    • Gaming
    • Laptops
    • Mobile
    • Software
    • Reviews
    • AI & Tech
    • Gadgets
    • How-To
    TechUpdateAlert
    Home»Mobile»Microsoft Knew of SharePoint Security Flaw but Failed to Effectively Patch It, Timeline Shows
    Mobile

    Microsoft Knew of SharePoint Security Flaw but Failed to Effectively Patch It, Timeline Shows

    techupdateadminBy techupdateadminJuly 23, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Microsoft Knew of SharePoint Security Flaw but Failed to Effectively Patch It, Timeline Shows
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A security patch Microsoft released this month failed to fully fix a critical flaw in the US tech giant’s SharePoint server software, opening the door to a sweeping global cyber espionage effort, a timeline reviewed by Reuters shows.

    On Tuesday, a Microsoft spokesperson confirmed that its initial solution to the flaw, identified at a hacker competition in May, did not work, but added that it released further patches that resolved the issue.

    It remains unclear who is behind the spy effort, which targeted about 100 organisations over the weekend, and is expected to spread as other hackers join the fray.

    In a blog post Microsoft said two allegedly Chinese hacking groups, dubbed “Linen Typhoon” and “Violet Typhoon,” were exploiting the weaknesses, along with a third, also based in China.

    Microsoft and Alphabet’s Google have said China-linked hackers were probably behind the first wave of hacks.

    Chinese government-linked operatives are regularly implicated in cyberattacks, but Beijing routinely denies such hacking operations.

    In an emailed statement, its embassy in Washington said China opposed all forms of cyberattacks, and “smearing others without solid evidence.”

    The vulnerability opening the way for the attack was first identified in May at a Berlin hacking competition organised by cybersecurity firm Trend Micro that offered cash bounties for finding computer bugs in popular software.

    It offered a $100,000 prize for so-called “zero-day” exploits that leverage previously undisclosed digital weaknesses that could be used against SharePoint, Microsoft’s flagship document management and collaboration platform.

    The US National Nuclear Security Administration, charged with maintaining and designing the nation’s cache of nuclear weapons, was among the agencies breached, Bloomberg News said on Tuesday, citing a person with knowledge of the matter.

    No sensitive or classified information is known to have been compromised, it added.

    The US Energy Department, the US Cybersecurity and Infrastructure Security Agency, and Microsoft did not immediately respond to Reuters’ requests for comment on the report.

    A researcher for the cybersecurity arm of Viettel, a telecoms firm run by Vietnam’s military, identified a SharePoint bug at the May event, dubbed it “ToolShell” and demonstrated a way to exploit it.

    The discovery won the researcher an award of $100,000, an X posting by Trend Micro’s “Zero Day Initiative” showed.

    Participating vendors were responsible for patching and disclosing security flaws in “an effective and timely manner,” Trend Micro said in a statement.

    “Patches will occasionally fail,” it added. “This has happened with SharePoint in the past.”

    In a July 8 security update Microsoft said it had identified the bug, listed it as a critical vulnerability, and released patches to fix it.

    About 10 days later, however, cybersecurity firms started to notice an influx of malicious online activity targeting the same software the bug sought to exploit: SharePoint servers.

    “Threat actors subsequently developed exploits that appear to bypass these patches,” British cybersecurity firm Sophos said in a blog post on Monday.

    The pool of potential ToolShell targets remains vast.

    Hackers could theoretically have already compromised more than 8,000 servers online, data from search engine Shodan, which helps identify internet-linked equipment, shows.

    Such servers were in networks ranging from auditors, banks, healthcare companies and major industrial firms to U.S. state-level and international government bodies.

    The Shadowserver Foundation, which scans the internet for potential digital vulnerabilities, put the number at a little more than 9,000, cautioning that the figure is a minimum.

    It said most of those affected were in the United States and Germany.

    Germany’s federal office for information security, BSI, said on Tuesday it had found no compromised SharePoint servers in government networks, despite some being vulnerable to the ToolShell attack.

    © Thomson Reuters 2025

    Effectively Failed Flaw Knew Microsoft patch security SharePoint Shows Timeline
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe Wyze Cam Vase hides a security camera in plain sight
    Next Article Peacock’s New Subscription Pricing Is Here. Here’s What to Know
    techupdateadmin
    • Website

    Related Posts

    Mobile

    A Realme 15 Pro Game of Thrones Limited Edition is coming

    August 9, 2025
    Laptops

    Diablo Lead Is Once Again Leaving Microsoft

    August 9, 2025
    Mobile

    Today’s NYT Wordle Hints, Answer and Help for Aug. 9 #1512

    August 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Apple Pencil With ‘Trackball’ Tip, Ability to Draw on Any Surface Described in Patent Document

    July 9, 20253 Views

    Samsung Galaxy Z Fold 7 and Galaxy Z Flip 7: First Impressions

    July 9, 20253 Views

    The Bezos-funded climate satellite is lost in space

    July 9, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Fitbit fitness trackers and watches in 2025

    July 9, 20250 Views

    There are still 200+ Prime Day 2025 deals you can get

    July 9, 20250 Views

    The best earbuds we’ve tested for 2025

    July 9, 20250 Views
    Our Picks

    Best Mobile Phones Under Rs. 15,000 in India: From iQOO Z10X, Poco M7 Pro, Moto G85 and More

    August 9, 2025

    I watched Wednesday season 2, part 1 and the family drama makes it even better than its predecessor

    August 9, 2025

    Infinix Hot 60i 5G India Launch Confirmed; Will Debut With Dimensity 6400 SoC, 50-Megapixel Rear Camera

    August 9, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    © 2025 techupdatealert. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.