Microsoft attributes on-premises SharePoint exploitation to Chinese state actors
Summary
Bottom line: Microsoft tied active exploitation of on-premises SharePoint flaws to Linen Typhoon, Violet Typhoon and Storm-2603, with post-exploitation key theft enabling persistent access. Rotate machine keys after patching, because patching alone does not evict the actor.
Key claims· extracted from reporting
- Bottom line: Microsoft tied active exploitation of on-premises SharePoint flaws to Linen Typhoon, Violet Typhoon and Storm-2603, with post-exploitation key theft enabling persistent access.Med · 30%numbernamed entity×6Source: Microsoft Threat Intelligence
- Rotate machine keys after patching, because patching alone does not evict the actor.Low · 10%named entitySource: Microsoft Threat Intelligence
Heuristic extraction, verify against the original report before citing.
Tags· click to alert
Story timeline
- Jul 22, 2025·criticalcurrentMicrosoft Threat IntelligenceMicrosoft attributes on-premises SharePoint exploitation to Chinese state actors
- Oct 9, 2025·criticalGoogle Threat Intelligence Group / Mandiant
- Oct 21, 2025·highSecurityWeek
- Oct 21, 2025·highBleepingComputer