financetom
Technology
financetom
/
Technology
/
Microsoft knew of SharePoint server exploit but failed to effectively patch it
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft knew of SharePoint server exploit but failed to effectively patch it
Jul 22, 2025 7:41 AM

*

Ongoing attacks compromised around 100 organisations over

weekend

*

SharePoint vulnerability identified during hacker

competition

*

Microsoft ( MSFT ) subsequently released patch that did not fix

flaw

By James Pearson

LONDON, July 22 (Reuters) - A security patch released by

Microsoft ( MSFT ) last month failed to fully fix a critical

flaw in U.S. tech giant's SharePoint server software that had

been identified in May, opening the door to a sweeping global

cyber espionage operation.

It remains unclear who is behind the ongoing operation,

which targeted around 100 organisations over the weekend. But

Alphabet's Google, which has visibility into wide

swathes of internet traffic, said it tied at least some of the

hacks to a "China-nexus threat actor".

The Chinese Embassy in Washington did not respond to a

Reuters request for comment. Chinese government-linked

operatives are regularly implicated in cyberattacks, but Beijing

routinely denies carrying out hacking operations.

Contacted on Tuesday, Microsoft ( MSFT ) was not immediately able to

provide comment on the patch and its effectiveness.

The vulnerability that facilitated the attack was first

identified in May at a hacking competition in Berlin organised

by cybersecurity firm Trend Micro ( TMICF ), which offered cash

bounties for the discovery of computer bugs in popular

software.

It offered a $100,000 prize for "zero day" exploits - so

called because they leverage previously undisclosed digital

weaknesses - that could be used against SharePoint, Microsoft's ( MSFT )

flagship document management and collaboration platform.

A researcher working for the cybersecurity arm of Viettel, a

telecommunications firm operated by Vietnam's military,

identified a SharePoint bug at the event, dubbed it 'ToolShell'

and demonstrated a method of exploiting it.

The researcher was awarded $100,000 for the discovery,

according to a post on X by Trend Micro's ( TMICF ) "Zero Day

Initiative". A spokesperson for Trend Micro ( TMICF ) did not immediately

respond to Reuters' requests for comment regarding the

competition on Tuesday.

Microsoft ( MSFT ) subsequently said in a July 8 security update that

it had identified the bug, listed it as a critical

vulnerability, and released patches to fix it.

Around 10 days later, however, cybersecurity firms started

to notice an influx of malicious online activity targeting the

same software the bug sought to exploit: SharePoint servers.

"Threat actors subsequently developed exploits that appear

to bypass these patches," British cybersecurity firm Sophos said

in a blog post on Monday.

The pool of potential ToolShell targets remains vast.

According to data from Shodan, a search engine that helps to

identify internet-linked equipment, over 8,000 servers online

could theoretically have already been compromised by hackers.

The Shadowserver Foundation, which scans the internet for

potential digital vulnerabilities, put the number at a little

more than 9,000, while cautioning that the figure was a minimum.

Those servers include major industrial firms, banks,

auditors, healthcare companies, and several U.S. state-level and

international government entities.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Check Out What Whales Are Doing With INTC
Check Out What Whales Are Doing With INTC
Feb 3, 2025
Investors with a lot of money to spend have taken a bearish stance on Intel ( INTC ) . And retail traders should know. We noticed this today when the trades showed up on publicly available options history that we track here at Benzinga. Whether these are institutions or just wealthy individuals, we don't know. But when something this big...
IBM Options Trading: A Deep Dive into Market Sentiment
IBM Options Trading: A Deep Dive into Market Sentiment
Feb 3, 2025
Deep-pocketed investors have adopted a bullish approach towards IBM ( IBM ) , and it's something market players shouldn't ignore. Our tracking of public options records at Benzinga unveiled this significant move today. The identity of these investors remains unknown, but such a substantial move in IBM ( IBM ) usually suggests something big is about to happen. We gleaned...
Samsung's Jay Y. Lee Acquitted, Shifting Focus To Business Challenges
Samsung's Jay Y. Lee Acquitted, Shifting Focus To Business Challenges
Feb 3, 2025
Seoul High Court on Monday acquitted consumer electronics company Samsung Electronics Co ( SSNLF )  executive Chair Jay Y. Lee of fraud and stock-rigging charges. The ruling removes a legal hurdle for Lee as Samsung navigates business challenges. Lee has faced graft allegations since 2017, Bloomberg reports. Also Read: Samsung Taps Google AI, Qualcomm Tech for Galaxy S25 to Rival Apple’s iPhone...
GameStop's Options: A Look at What the Big Money is Thinking
GameStop's Options: A Look at What the Big Money is Thinking
Feb 3, 2025
High-rolling investors have positioned themselves bearish on GameStop ( GME ) , and it's important for retail traders to take note. This activity came to our attention today through Benzinga's tracking of publicly available options data. The identities of these investors are uncertain, but such a significant move in GME often signals that someone has privileged information. Today, Benzinga's options...
Copyright 2023-2025 - www.financetom.com All Rights Reserved