{"id":5435,"date":"2025-07-25T06:11:15","date_gmt":"2025-07-25T05:11:15","guid":{"rendered":"https:\/\/inkr.sk\/?post_type=nwes&#038;p=5435"},"modified":"2025-07-23T06:14:13","modified_gmt":"2025-07-23T05:14:13","slug":"5430","status":"publish","type":"nwes","link":"https:\/\/inkr.sk\/en\/nwes\/5430\/","title":{"rendered":"A SharePoint vulnerability gave Chinese hackers access to government systems"},"content":{"rendered":"\n<p>This month&#8217;s Microsoft security update failed to fully patch a critical vulnerability in SharePoint server software, paving the way for a large-scale global cyber-espionage campaign, according to a timeline reviewed by Reuters.<\/p>\n\n\n\n<p>On Tuesday, a Microsoft spokesperson confirmed that the initial patch \u2014 intended to fix the vulnerability discovered during a hacking competition in May \u2014 did not work. However, the company has since issued additional patches which it says have resolved the issue.<\/p>\n\n\n\n<p>It remains unclear who exactly is behind the attack, which affected around 100 organizations over the weekend. The scale of malicious activity is expected to grow, as other hacker groups may join in.<\/p>\n\n\n\n<p>Microsoft&#8217;s blog states that at least two Chinese hacking groups \u2014 Linen Typhoon and Violet Typhoon \u2014 as well as a third, also based in China, are involved in the attacks.<\/p>\n\n\n\n<p>Microsoft and Google (Alphabet\u2019s division) both stated that Chinese-linked hackers are likely behind the first wave of attacks. China traditionally denies involvement in any cyberattacks.<\/p>\n\n\n\n<p>In response to Reuters, the Chinese embassy in Washington stated that China opposes all forms of cyberattacks and condemns &#8220;groundless accusations.&#8221;<\/p>\n\n\n\n<p>The vulnerability that enabled these attacks was first identified in May during a hacking contest in Berlin, organized by cybersecurity firm Trend Micro. It offered a $100,000 reward for zero-day exploits \u2014 previously unknown flaws \u2014 targeting software such as SharePoint.<\/p>\n\n\n\n<p>Among the potential targets was the U.S. National Nuclear Security Administration, responsible for the country\u2019s nuclear arsenal. According to Bloomberg, data from this agency was also accessed, though no leak of confidential or classified information has been confirmed.<\/p>\n\n\n\n<p>A researcher from Viettel, a Vietnamese military-controlled telecom company, discovered the vulnerability during the May event, named it ToolShell, and demonstrated its use. He received $100,000 through Trend Micro\u2019s Zero Day initiative.<\/p>\n\n\n\n<p>Trend Micro emphasized that software vendors are responsible for timely patching. \u201cPatches sometimes fail. This has happened with SharePoint before,\u201d the company said in a statement.<\/p>\n\n\n\n<p>In its July 8 security update, Microsoft classified the vulnerability as critical and released patches. However, within 10 days, cybersecurity firms observed a wave of malicious activity targeting the same SharePoint servers.<\/p>\n\n\n\n<p>British firm Sophos reported Monday that attackers developed exploits capable of bypassing Microsoft\u2019s patches.<\/p>\n\n\n\n<p>The number of potentially vulnerable ToolShell targets remains very high. According to search engine Shodan, which tracks internet-connected devices, hackers could potentially compromise over 8,000 servers.<\/p>\n\n\n\n<p>These servers are located in the networks of auditing firms, banks, healthcare providers, industrial companies, U.S. government agencies, and international organizations.<\/p>\n\n\n\n<p>The Shadowserver Foundation, which scans the internet for vulnerabilities, counted over 9,000 potentially compromised servers, calling it a conservative estimate. Most affected are in the U.S. and Germany.<\/p>\n\n\n\n<p>Germany\u2019s Federal Office for Information Security (BSI) stated Tuesday that no government SharePoint servers were breached, though some were vulnerable to ToolShell.<\/p>\n","protected":false},"featured_media":5432,"template":"","class_list":["post-5435","nwes","type-nwes","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>A SharePoint vulnerability gave Chinese hackers access to government systems - INKR<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/inkr.sk\/nwes\/5430\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A SharePoint vulnerability gave Chinese hackers access to government systems - INKR\" \/>\n<meta property=\"og:description\" content=\"This month&#8217;s Microsoft security update failed to fully patch a critical vulnerability in SharePoint server software, paving the way for a large-scale global cyber-espionage campaign, according to a timeline reviewed by Reuters. On Tuesday, a Microsoft spokesperson confirmed that the initial patch \u2014 intended to fix the vulnerability discovered during a hacking competition in May [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/inkr.sk\/nwes\/5430\/\" \/>\n<meta property=\"og:site_name\" content=\"INKR\" \/>\n<meta property=\"og:image\" content=\"https:\/\/inkr.sk\/wp-content\/uploads\/image-15.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1184\" \/>\n\t<meta property=\"og:image:height\" content=\"672\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/\",\"url\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/\",\"name\":\"A SharePoint vulnerability gave Chinese hackers access to government systems - INKR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/inkr.sk\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/inkr.sk\\\/wp-content\\\/uploads\\\/image-15.png\",\"datePublished\":\"2025-07-25T05:11:15+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/#primaryimage\",\"url\":\"https:\\\/\\\/inkr.sk\\\/wp-content\\\/uploads\\\/image-15.png\",\"contentUrl\":\"https:\\\/\\\/inkr.sk\\\/wp-content\\\/uploads\\\/image-15.png\",\"width\":1184,\"height\":672},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/inkr.sk\\\/nwes\\\/5430\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"INKR\",\"item\":\"https:\\\/\\\/inkr.sk\\\/ru\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A SharePoint vulnerability gave Chinese hackers access to government systems\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/inkr.sk\\\/#website\",\"url\":\"https:\\\/\\\/inkr.sk\\\/\",\"name\":\"INKR\",\"description\":\"INKR\",\"publisher\":{\"@id\":\"https:\\\/\\\/inkr.sk\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/inkr.sk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/inkr.sk\\\/#organization\",\"name\":\"INKR\",\"url\":\"https:\\\/\\\/inkr.sk\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/inkr.sk\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/inkr.sk\\\/wp-content\\\/uploads\\\/cropped-INKR.jpg\",\"contentUrl\":\"https:\\\/\\\/inkr.sk\\\/wp-content\\\/uploads\\\/cropped-INKR.jpg\",\"width\":512,\"height\":512,\"caption\":\"INKR\"},\"image\":{\"@id\":\"https:\\\/\\\/inkr.sk\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A SharePoint vulnerability gave Chinese hackers access to government systems - INKR","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/inkr.sk\/nwes\/5430\/","og_locale":"en_US","og_type":"article","og_title":"A SharePoint vulnerability gave Chinese hackers access to government systems - INKR","og_description":"This month&#8217;s Microsoft security update failed to fully patch a critical vulnerability in SharePoint server software, paving the way for a large-scale global cyber-espionage campaign, according to a timeline reviewed by Reuters. On Tuesday, a Microsoft spokesperson confirmed that the initial patch \u2014 intended to fix the vulnerability discovered during a hacking competition in May [&hellip;]","og_url":"https:\/\/inkr.sk\/nwes\/5430\/","og_site_name":"INKR","og_image":[{"width":1184,"height":672,"url":"https:\/\/inkr.sk\/wp-content\/uploads\/image-15.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/inkr.sk\/nwes\/5430\/","url":"https:\/\/inkr.sk\/nwes\/5430\/","name":"A SharePoint vulnerability gave Chinese hackers access to government systems - INKR","isPartOf":{"@id":"https:\/\/inkr.sk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/inkr.sk\/nwes\/5430\/#primaryimage"},"image":{"@id":"https:\/\/inkr.sk\/nwes\/5430\/#primaryimage"},"thumbnailUrl":"https:\/\/inkr.sk\/wp-content\/uploads\/image-15.png","datePublished":"2025-07-25T05:11:15+00:00","breadcrumb":{"@id":"https:\/\/inkr.sk\/nwes\/5430\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/inkr.sk\/nwes\/5430\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/inkr.sk\/nwes\/5430\/#primaryimage","url":"https:\/\/inkr.sk\/wp-content\/uploads\/image-15.png","contentUrl":"https:\/\/inkr.sk\/wp-content\/uploads\/image-15.png","width":1184,"height":672},{"@type":"BreadcrumbList","@id":"https:\/\/inkr.sk\/nwes\/5430\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"INKR","item":"https:\/\/inkr.sk\/ru\/"},{"@type":"ListItem","position":2,"name":"A SharePoint vulnerability gave Chinese hackers access to government systems"}]},{"@type":"WebSite","@id":"https:\/\/inkr.sk\/#website","url":"https:\/\/inkr.sk\/","name":"INKR","description":"INKR","publisher":{"@id":"https:\/\/inkr.sk\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/inkr.sk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/inkr.sk\/#organization","name":"INKR","url":"https:\/\/inkr.sk\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/inkr.sk\/#\/schema\/logo\/image\/","url":"https:\/\/inkr.sk\/wp-content\/uploads\/cropped-INKR.jpg","contentUrl":"https:\/\/inkr.sk\/wp-content\/uploads\/cropped-INKR.jpg","width":512,"height":512,"caption":"INKR"},"image":{"@id":"https:\/\/inkr.sk\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/inkr.sk\/en\/wp-json\/wp\/v2\/nwes\/5435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/inkr.sk\/en\/wp-json\/wp\/v2\/nwes"}],"about":[{"href":"https:\/\/inkr.sk\/en\/wp-json\/wp\/v2\/types\/nwes"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/inkr.sk\/en\/wp-json\/wp\/v2\/media\/5432"}],"wp:attachment":[{"href":"https:\/\/inkr.sk\/en\/wp-json\/wp\/v2\/media?parent=5435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}