October 09, 2026 05:03 pm (IST)
Follow us:
facebook-white sharing button
twitter-white sharing button
instagram-white sharing button
youtube-white sharing button
‘Restriction, not complete closure’: Supreme Court questions Delhi shutdown ahead of CJP protest | 'Unwarranted': India hits back at JD Vance over ‘indentured servants’ remark amid US Green Card crackdown | US targets Microsoft, Infosys, Tata in green card crackdown | ‘Bold and inventive’: Canadian poet Anne Carson wins 2026 Nobel Prize in Literature | ‘Attempt to destabilise world’s largest democracy’: 42 retired judges rally behind Gyanesh Kumar over ‘vote chori’ row | ‘Vote chor, gaddi chod’: Dhruv Rathee, Prakash Raj join Bengaluru protest against Gyanesh Kumar | India condemns Houthi attacks on Saudi airports, calls targeting of civilian infrastructure unacceptable | Dalal Street bloodbath: Investors lose Rs. 8 lakh crore as Sensex crashes over 1,000 points | Amazon layoffs hit India, US and UK: Fresh job cuts rock e-commerce giant amid festive shopping season | Bollywood mourns Nana Patekar: Anupam Kher, Akshay Kumar, Jr NTR, Suniel Shetty pay emotional tributes
Microsoft
The Microsoft logo. Photo: Unsplash

Chinese hacking group behind recent attacks on SharePoint: Microsoft

| @indiablooms | Jul 25, 2025, at 06:26 pm

Tech giant Microsoft has said Chinese hacking groups were believed to be behind the recent attacks on its SharePoint collaboration software.

In a blog post, Microsoft said: "As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint servers."

"In addition, we have observed another China-based threat actor, tracked as Storm-2603, exploiting these vulnerabilities to deploy ransomware. Investigations into other actors also using these exploits are still ongoing," the statement said.

"With the rapid adoption of these exploits, Microsoft assesses with high confidence that threat actors will continue to integrate them into their attacks against unpatched on-premises SharePoint systems," the statement further said.

Alerting users, Microsoft recommended that customers use supported versions of on-premises SharePoint servers with the latest security updates.

"To stop unauthenticated attacks from exploiting this vulnerability, customers should also integrate and enable Antimalware Scan Interface (AMSI) and Microsoft Defender Antivirus (or equivalent solutions) for all on-premises SharePoint deployments and configure AMSI to enable Full Mode," the tech giant said.

Support Our Journalism

We cannot do without you.. your contribution supports unbiased journalism

IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.

Support objective journalism for a small contribution.