Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Google, Microsoft say SharePoint attacks tied to China

Security researchers from Google and Microsoft have identified a zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770.

The flaw is being exploited by China-linked hacking groups, including “Linen Typhoon,” “Violet Typhoon,” and “Storm-2603.”

Discovered last weekend, the vulnerability allows attackers to steal private keys, install malware, and access files on compromised servers.

Microsoft said attacks have been occurring since at least July 7.

Charles Carmakal, CTO at Google’s Mandiant, confirmed that multiple actors are exploiting the flaw. At least one group is connected to China.

China has denied involvement, stating it opposes all cybercrime.

Recent Microsoft developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.