• Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

US Tops Hit List as 396 SharePoint Systems Compromised Globally

Jane Doe by Jane Doe
July 30, 2025
in Cyber
Share on FacebookShare on Twitter

A widespread cyber-espionage campaign exploiting critical vulnerabilities in Microsoft SharePoint servers has compromised at least 396 organizations globally, with the United States emerging as the primary target. The attacks, linked to state-sponsored Chinese hacking groups, have sent shockwaves through government agencies, critical infrastructure, and private enterprises worldwide, underscoring the escalating threat to on-premises software systems.

Initial reports from Dutch cybersecurity firm Eye Security, which first identified the ongoing attacks, indicated around 100 victims. However, follow-up scans have revealed the true scale of the breach, with the number of compromised systems nearly quadrupling in just over a week. Researchers warn that the actual figure could be significantly higher, as not all attack methods leave detectable traces.

The sophisticated campaign leverages unpatched zero-day vulnerabilities (CVE-2025-53770 and CVE-2025-53771) in on-premises SharePoint Server versions (2016, 2019, and Subscription Edition), allowing attackers to gain full control of servers, steal cryptographic keys, install backdoors, and maintain persistent access even after patching. Microsoft has explicitly stated that its cloud-based SharePoint Online service is not affected by these particular vulnerabilities.

Read

PAGERDUTY Confirms Data Breach After Salesforce Account Compromise

Thailand’s PDPA Crackdown 2025: Major Fines and Lessons from Latest Enforcement

Among the high-profile victims in the US are federal agencies, including the National Nuclear Security Administration (NNSA) and departments of Energy, Homeland Security, and Health and Human Services. While officials have stated that sensitive or classified information was not reportedly compromised in the NNSA breach, the incident highlights the severe risk posed by these vulnerabilities to national security. Other affected entities include the US Education Department, Florida’s Department of Revenue, and the Rhode Island General Assembly.

Microsoft has attributed a significant portion of the hacking activity to three China-linked groups: Linen Typhoon, Violet Typhoon, and Storm-2603, noting their focus on intellectual property theft, espionage, and, more recently, ransomware deployment. The latest attacks involve the deployment of “Warlock” ransomware, aimed at paralyzing networks and extorting cryptocurrency payments.

In response to the escalating crisis, Microsoft has released emergency patches and urged all affected organizations to apply them immediately. The Cybersecurity and Infrastructure Security Agency (CISA) has also added the vulnerabilities to its Known Exploited Vulnerabilities list, mandating federal agencies to remediate their systems without delay. Beyond patching, experts emphasize the crucial need for organizations to rotate all compromised cryptographic keys, enable Antimalware Scan Interface (AMSI) integration, and conduct thorough threat hunting to detect and eradicate any persistent access.

The incident serves as a stark reminder for organizations to re-evaluate their risk calculus regarding on-premises solutions and consider transitioning to cloud-based services where appropriate, or to implement robust cybersecurity measures for their self-hosted environments. The global nature and severity of this attack underscore the continuous need for vigilance and proactive security postures in an increasingly complex cyber landscape.

Previous Post

U.S. Fermilab hit in cyberattack targeting Microsoft’s SharePoint: Report

Next Post

Palo Alto Networks Announces Agreement to Acquire CyberArk, the Identity Security Leader

Jane Doe

Jane Doe

More Articles

UN Creates Two Mechanisms for Global Governance of AI
Cyber

French Retail Giant Auchan Discloses Cyberattack on Loyalty Accounts

French retail giant Auchan has confirmed that a cyberattack compromised the personal data of several hundred thousand customers, with the...

by Jane Doe
September 3, 2025
UN Creates Two Mechanisms for Global Governance of AI
Cyber

Hackers Breach Fintech Firm in Attempted $130M Bank Heist

A major Brazilian fintech company, Sinqia S.A., has revealed that it was the target of a sophisticated cyberattack on August...

by Jane Doe
September 3, 2025
UN Creates Two Mechanisms for Global Governance of AI
Cyber

A Decade of Strengthening Singapore’s Cyber Defence Amid Escalating Threats

Over the last ten years, Singapore has systematically built a formidable cyber defence framework, positioning itself as a global leader...

by Jane Doe
September 3, 2025
UN Creates Two Mechanisms for Global Governance of AI
Cyber

Pentera Announces Automated Security Validation for Cl0p – Most Active Ransomware Group in 2025

Cybersecurity company Pentera has unveiled a new automated security validation module designed to test and fortify defenses against the Cl0p...

by Jane Doe
September 3, 2025
Next Post
Cognizant Launches AI Training Data Services to Accelerate AI Model Development at Enterprise Scale

Palo Alto Networks Announces Agreement to Acquire CyberArk, the Identity Security Leader

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Latest News

Hacking AI the Right Way: A Guide to AI Red Teaming

Hacking AI the Right Way: A Guide to AI Red Teaming

May 27, 2025
Researchers Cracked the Encryption Used by DarkBit Ransomware

Researchers Cracked the Encryption Used by DarkBit Ransomware

August 12, 2025
Researchers Cracked the Encryption Used by DarkBit Ransomware

High-severity WinRAR 0-day exploited for weeks by 2 groups

August 12, 2025

Transforming App Development with AI, Part 3: Challenges and Ethical Considerations

March 19, 2025
Exploring AI’s Critical Role in Climate Change at the G7 Summit

Exploring AI’s Critical Role in Climate Change at the G7 Summit

May 28, 2025
Are We Ready for the Next Cyber Storm? Why Staying Passive Is the Greatest Risk

Are We Ready for the Next Cyber Storm?

April 26, 2025
Researchers Cracked the Encryption Used by DarkBit Ransomware

Ghanaian Nationals Extradited for Roles in $100M Romance and Wire Fraud

August 12, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.