Blame a leak for Microsoft SharePoint attacks, researcher insists

Researcher Claims Microsoft SharePoint Attacks Were Caused by a Leak
Photo: theregister.com

Researcher Claims Microsoft SharePoint Attacks Were Caused by a Leak

Microsoft SharePoint servers have been the target of a series of cyberattacks, with the perpetrators bypassing recent security patches. These attacks, involving ransomware operators, Chinese state-sponsored hackers, and data thieves, exploited flaws in Microsoft’s SharePoint software. Researchers from Trend Micro’s Zero Day Initiative (ZDI) have traced the origins of the attack to a leak that revealed critical vulnerability details before official patches were released. In May 2025, during the Pwn2Own hacking competition, a researcher discovered an exploit involving a combination of authentication bypass and insecure deserialization bugs in SharePoint. Despite Microsoft receiving full details of the exploit in a private report, mass exploitation began in early July, just before the release of security patches. The issue appears to have been exacerbated by the early access to vulnerability information given to some security vendors through the Microsoft Active Protections Program (MAPP). Microsoft’s failure to fully patch the vulnerabilities allowed attackers to continue exploiting the flaw, and by mid-July, over 400 organizations had been compromised, including state-sponsored groups like Linen Typhoon and Violet Typhoon. As concerns about further leaks rise, experts are questioning whether the MAPP system is reliable enough to prevent these types of issues from happening again.

Leave a Reply

Your email address will not be published. Required fields are marked *