Threat Intelligence, Vulnerability Management, Patch/Configuration Management

Intrusions involving SharePoint exploits pinned on Chinese hacking operations

Microsoft SharePoint app seen in App Store on the screen of ipad and blurred finger pointing at it.

Chinese state-sponsored threat operations Linen Typhoon, also known as APT27, Emissary Panda, and Bronze Union, and Violet Typhoon, also known as APT31, Judgment Panda, and Bronze Vinewood, as well as the suspected China-based hacking group Storm-2603 have been targeting vulnerable internet-exposed Microsoft SharePoint servers impacted by the flaws, tracked as CVE-2025-53770 and CVE-2025-53771, since earlier this month, reports The Hacker News.

Attacks involving both vulnerabilities which stem from faulty patches for the remote code execution flaw CVE-2025-49704 and the impersonation bug CVE-2025-49706 have allowed malicious actors to circumvent authentication and run remote code to facilitate web shell deployment, subsequently resulting in MachineKey data exfiltration, according to a report from Microsoft. Further analysis of the SharePoint exploit by cybersecurity researcher Rakesh Krishnan revealed Network Utility Process, Crashpad Handler, and GPU Process invocation within Microsoft Edge, indicating sandbox evasion mechanisms. "With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems," said Microsoft, which called for the immediate application of updates and activation of both Microsoft Defender and Antimalware Scan Interface to mitigate potential compromise.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds