Chinese Hackers Exploit Microsoft SharePoint Zero-Day Vulnerability
Security researchers from Google and Microsoft have discovered that Chinese-backed hackers are actively exploiting a zero-day vulnerability in Microsoft SharePoint, a popular software used by organizations to manage and share internal documents. The flaw, identified as CVE-2025-53770, allows attackers to steal private keys from self-hosted SharePoint servers. Once exploited, hackers can plant malware, access sensitive documents, and even infiltrate other systems on the same network. Microsoft has attributed the attacks to several China-backed hacker groups, including Linen Typhoon, Violet Typhoon, and Storm-2603, with varying motives, ranging from intellectual property theft to espionage. The vulnerability has been active since at least July 7, 2025, and numerous organizations, particularly within the government sector, have already been affected. Microsoft has since rolled out patches to mitigate the risk, but experts warn that those with self-hosted SharePoint versions should assume they have been compromised. This latest attack is part of an ongoing series of cyberattacks attributed to China, including previous incidents targeting Microsoft Exchange servers in 2021.
