Security researchers at Google and Microsoft say they have evidence that hackers backed by China are exploiting a zero-day bug in Microsoft SharePoint, as companies around the world scramble to patch the flaw.

The bug, known officially as CVE-2025-53770 and discovered last weekend, allows hackers to steal sensitive private keys from self-hosted versions of SharePoint, a software server widely used by companies and organizations to store and share internal documents. Once exploited, an attacker can use the bug to remotely plant malware and gain access to the files and data stored within, as well as gain access to other systems on the same network.

  • Oisteink@feddit.nl
    link
    fedilink
    English
    arrow-up
    23
    ·
    16 days ago

    That’s not a zero-day… Really dislike media that waters down or misuse terminology

    • theunknownmuncher@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      16 days ago

      It’s not just media. The number of software engineers I’ve heard talk about “fixing” a “zero day” in a code dependency by updating to a patched version…

  • Dr. Moose@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    20
    ·
    edit-2
    16 days ago

    The attack exploits SharePoint vulnerabilities originally disclosed at a Berlin hacking competition in May, where a Vietnamese cybersecurity researcher received a $100,000 bounty for discovering the flaws. Reuters reported that Microsoft was allegedly informed of the vulnerabilities in May but failed to fully address them in an initial July patch

    And

    Several cybersecurity experts compared the SharePoint campaign to the 2021 Microsoft Exchange server attacks that compromised US government systems. Former FBI Cyber Unit deputy director Cynthia Kaiser warned that hackers “already in their systems may lie dormant for extended periods before operationalizing”

    Just shows in what a poor position US is now. Allies discovered it, reported it, feds didn’t prepare for it and Chinese are in. Incredible incompetence except for US allies that despite US’ isolationism still care.

    Source

  • just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    16 days ago

    This is what you get when you don’t patch your shit after being told about it MONTHS before it was demonstrated, and MONTHS after.

  • Cypher@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    16 days ago

    I have been dealing with this the last couple of days, Microsofts incompetence never fails to impress.