financetom
Business
financetom
/
Business
/
Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows
Jul 22, 2025 7:11 PM

*

Weekend attacks compromised about 100 organisations

*

May hacker contest uncovered SharePoint weak spot

*

Initial Microsoft ( MSFT ) patch did not fully fix flaw

By James Pearson

LONDON, July 22 (Reuters) - A security patch Microsoft ( MSFT )

released this month failed to fully fix a critical flaw

in the U.S. tech giant's SharePoint server software, opening the

door to a sweeping global cyber espionage effort, a timeline

reviewed by Reuters shows.

On Tuesday, a Microsoft ( MSFT ) spokesperson confirmed that its

initial solution to the flaw, identified at a hacker competition

in May, did not work, but added that it released further patches

that resolved the issue.

It remains unclear who is behind the spy effort, which

targeted about 100 organisations over the weekend, and is

expected to spread as other hackers join the fray.

In a blog post Microsoft ( MSFT ) said two allegedly Chinese hacking

groups, dubbed "Linen Typhoon" and "Violet Typhoon," were

exploiting the weaknesses, along with a third, also based in

China.

Microsoft ( MSFT ) and Alphabet's Google have said

China-linked hackers were probably behind the first wave of

hacks.

Chinese government-linked operatives are regularly

implicated in cyberattacks, but Beijing routinely denies such

hacking operations.

In an emailed statement, its embassy in Washington said

China opposed all forms of cyberattacks, and "smearing others

without solid evidence."

The vulnerability opening the way for the attack was first

identified in May at a Berlin hacking competition organised by

cybersecurity firm Trend Micro ( TMICF ) that offered cash

bounties for finding computer bugs in popular software.

It offered a $100,000 prize for so-called "zero-day"

exploits that leverage previously undisclosed digital weaknesses

that could be used against SharePoint, Microsoft's ( MSFT ) flagship

document management and collaboration platform.

The U.S. National Nuclear Security Administration, charged

with maintaining and designing the nation's cache of nuclear

weapons, was among the agencies breached, Bloomberg News said on

Tuesday, citing a person with knowledge of the matter.

No sensitive or classified information is known to have been

compromised, it added.

The U.S. Energy Department, the U.S. Cybersecurity and

Infrastructure Security Agency, and Microsoft ( MSFT ) did not

immediately respond to Reuters' requests for comment on the

report.

A researcher for the cybersecurity arm of Viettel, a

telecoms firm run by Vietnam's military, identified a SharePoint

bug at the May event, dubbed it "ToolShell" and demonstrated a

way to exploit it.

The discovery won the researcher an award of $100,000, an X

posting by Trend Micro's ( TMICF ) "Zero Day Initiative" showed.

Participating vendors were responsible for patching and

disclosing security flaws in "an effective and timely manner,"

Trend Micro ( TMICF ) said in a statement.

"Patches will occasionally fail," it added. "This has

happened with SharePoint in the past."

In a July 8 security update Microsoft ( MSFT ) said it had identified

the bug, listed it as a critical vulnerability, and released

patches to fix it.

About 10 days later, however, cybersecurity firms started to

notice an influx of malicious online activity targeting the same

software the bug sought to exploit: SharePoint servers.

"Threat actors subsequently developed exploits that appear

to bypass these patches," British cybersecurity firm Sophos said

in a blog post on Monday.

The pool of potential ToolShell targets remains vast.

Hackers could theoretically have already compromised more

than 8,000 servers online, data from search engine Shodan, which

helps identify internet-linked equipment, shows.

Such servers were in networks ranging from auditors, banks,

healthcare companies and major industrial firms to U.S.

state-level and international government bodies.

The Shadowserver Foundation, which scans the internet for

potential digital vulnerabilities, put the number at a little

more than 9,000, cautioning that the figure is a minimum.

It said most of those affected were in the United States and

Germany.

Germany's federal office for information security, BSI, said

on Tuesday it had found no compromised SharePoint servers in

government networks, despite some being vulnerable to the

ToolShell attack.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
New Found Gold to Buy Remaining Royalty Interests at Queensway for $1 Million
New Found Gold to Buy Remaining Royalty Interests at Queensway for $1 Million
Oct 15, 2024
07:27 AM EDT, 10/15/2024 (MT Newswires) -- New Found Gold ( NFGC ) on Tuesday said it has elected to purchase the remaining royalty on its Golden Bullet property from three arm's length royalty holders for $1 million in total. New Found purchased 0.6% of the vendors' 1.6% net smelter returns royalty on the Golden Bullet property and had the...
Montrose Environmental Group Wins $249 Million Environmental Services Contract
Montrose Environmental Group Wins $249 Million Environmental Services Contract
Oct 15, 2024
07:42 AM EDT, 10/15/2024 (MT Newswires) -- Montrose Environmental Group ( MEG ) said Tuesday it has won a $249 million five-year contract to provide environmental quality services to a division of the US Army Corps of Engineers. The contract meant for the Mobile District, South Atlantic Division, focuses on air and water quality compliance, pollution prevention and hazardous waste,...
Sila Realty Trust Says Florida, Georgia Properties Operational After Hurricanes
Sila Realty Trust Says Florida, Georgia Properties Operational After Hurricanes
Oct 15, 2024
07:22 AM EDT, 10/15/2024 (MT Newswires) -- Sila Realty Trust ( SILA ) said Tuesday that its properties in Florida and Georgia, impacted by Hurricane Helene and Hurricane Milton, are fully operational after assessment. Sila Realty ( SILA ) said it will collaborate with tenants to address minor damage while supporting efforts to restore normalcy in the affected communities. ...
Akamai Technologies Partners with Kyndryl to Enhance Micro-Segmentation Services
Akamai Technologies Partners with Kyndryl to Enhance Micro-Segmentation Services
Oct 15, 2024
07:23 AM EDT, 10/15/2024 (MT Newswires) -- Akamai Technologies ( AKAM ) said Tuesday it collaborated with Kyndryl ( KD ) to deliver micro-segmentation implementation services with Akamai Guardicore Segmentation. The company said Kyndryl's ( KD ) certified teams will deliver implementation and managed services for Akamai Guardicore Segmentation, enhancing Kyndryl's ( KD ) Zero Trust Services and addressing specific...
Copyright 2023-2026 - www.financetom.com All Rights Reserved