financetom
Technology
financetom
/
Technology
/
Microsoft probing if Chinese hackers learned SharePoint flaws through alert, Bloomberg News reports
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Microsoft probing if Chinese hackers learned SharePoint flaws through alert, Bloomberg News reports
Jul 25, 2025 10:59 PM

*

Microsoft ( MSFT ) evaluates partner program security amid leak

concerns

*

Program aims to give security vendors a head start against

hackers

July 25 (Reuters) - Microsoft ( MSFT ) is investigating

whether a leak from its early alert system for cybersecurity

companies allowed Chinese hackers to exploit flaws in its

SharePoint service before they were patched, Bloomberg News

reported on Friday.

A security patch Microsoft ( MSFT ) released this month failed to fully

fix a critical flaw in the U.S. tech giant's SharePoint server

software, opening the door to a sweeping global cyber espionage

effort.

In a blog post on Tuesday, Microsoft ( MSFT ) said two allegedly

Chinese hacking groups, dubbed "Linen Typhoon" and "Violet

Typhoon," were exploiting the weaknesses, along with a third,

also based in China.

The tech giant is probing if a leak from the Microsoft

Active Protections Program (MAPP) led to the widespread

exploitation of vulnerabilities in its SharePoint software

globally over the past several days, the report said.

Microsoft ( MSFT ) said in a statement provided to Reuters that the

company continually evaluates "the efficacy and security of all

of our partner programs and makes the necessary improvements as

needed."

A researcher with Vietnamese cybersecurity firm Viettel

demonstrated the SharePoint vulnerability in May at the Pwn2Own

cybersecurity conference in Berlin. The conference, put on by

cybersecurity company Trend Micro's Zero Day Initiative, rewards

researchers in the pursuit of ethically disclosing software

vulnerabilities.

The researcher, Dinh Ho Anh Khoa, was awarded $100,000 and

Microsoft ( MSFT ) issued an initial patch for the vulnerability in July,

but members of the MAPP program were notified of the

vulnerabilities on June 24, July 3 and July 7, Dustin Childs,

head of threat awareness for the Zero Day Initiative at Trend

Micro, told Reuters Friday.

Microsoft ( MSFT ) first observed exploit attempts on July 7, the

company said in the Tuesday blog post.

Childs told Reuters that "the likeliest scenario is that

someone in the MAPP program used that information to create the

exploits."

It's not clear which vendor was responsible, Childs said,

"but since many of the exploit attempts come from China, it

seems reasonable to speculate it was a company in that region."

It would not be the first time that a leak from the MAPP

program led to a security breach. More than a decade ago,

Microsoft ( MSFT ) accused a Chinese firm, Hangzhou DPTech Technologies

Co., Ltd., of breaching its non-disclosure agreement and

expelled it from the program.

"We recognize that there is the potential for vulnerability

information to be misused," Microsoft ( MSFT ) said in a 2012 blog post,

around the time that information first leaked from the program.

"In order to limit this as much as possible, we have strong

non-disclosure agreements (NDA) with our partners. Microsoft ( MSFT )

takes breaches of its NDAs very seriously."

Any confirmed leak from MAPP would be a blow to the program,

which is meant to give cyber defenders the upper hand against

hackers who race to parse Microsoft ( MSFT ) updates for clues on how to

develop malicious software that can be used against

still-vulnerable users.

Launched in 2008, MAPP was meant to give trusted security

vendors a head start against the hackers, for example, by

supplying them with detailed technical information and, in some

cases, "proof of concept" software that mimics the operation of

genuine malware.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Analysis-BOJ's victory lap on deflation paves way for rate-hike cycle
Analysis-BOJ's victory lap on deflation paves way for rate-hike cycle
Jul 28, 2024
TOKYO (Reuters) - The Bank of Japan is setting the stage for an era of steady interest rate hikes by claiming victory in its long battle with deflation, sources and analysts say, in a major review of past policy that nods to significant consumer behaviour shifts. The findings would highlight how the central bank is drawing a line under former...
Taiwan Q2 economic growth seen slowing, but supported by AI boom: Reuters poll
Taiwan Q2 economic growth seen slowing, but supported by AI boom: Reuters poll
Jul 28, 2024
TAIPEI (Reuters) - Economic growth in trade-dependent Taiwan probably slowed in the second quarter in spite of robust exports driven by high demand for AI technology, a Reuters poll showed on Monday. Gross domestic product (GDP) in April-June was expected to have expanded 4.8% from a year earlier, down from 6.56% in the first quarter, according to the median forecast...
What Analysts Are Saying About Teradyne Stock
What Analysts Are Saying About Teradyne Stock
Jul 29, 2024
Across the recent three months, 19 analysts have shared their insights on Teradyne ( TER ) , expressing a variety of opinions spanning from bullish to bearish. The following table encapsulates their recent ratings, offering a glimpse into the evolving sentiments over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish...
Telecoms installations vandalised in France - Le Parisien, BFM TV
Telecoms installations vandalised in France - Le Parisien, BFM TV
Jul 29, 2024
PARIS (Reuters) - Telecom installations belonging to French companies SFR and Bouygues Telecom have been vandalised, reported Le Parisien newspaper and BFM TV on Monday, citing unnamed sources. SFR and Bouygues did not immediately respond to requests for comment. The reports said cables in electrical cabinets had been cut in southern France, and that installations in the Meuse region near...
Copyright 2023-2025 - www.financetom.com All Rights Reserved