CRN has learned about the involvement of at least one server from China in a cyberattack on Microsoft
- Новости
- World
- CRN has learned about the involvement of at least one server from China in a cyberattack on Microsoft
A cyberattack on the SharePoint program from the American Microsoft corporation could have been carried out using at least one Chinese server. This was announced on July 21 by Charles Karmakal, technical director of Mandiant Consulting, owned by Google Cloud.
"We believe that at least one of the actors responsible for this early exploitation is a China—related threat actor," CRN magazine quoted him as saying.
According to him, the company expects that the trend towards such attacks will only continue, as hackers will use the same vulnerability to commit new hacks.
In addition, the interlocutors of the publication suggested that the weakness in the program's security system would be exploited not only by hackers acting in the interests of other states, but also by financially interested persons.
"The ToolShell cyberattack involves the use of local Microsoft SharePoint servers using a critical remote code execution vulnerability (CVE-2025-53770) related to a spoofing vulnerability (CVE-2025-53771)," the publication says.
On July 20, hackers exploited a vulnerability in Microsoft's SharePoint program to launch cyber attacks on American government agencies, universities, and commercial organizations. Experts estimate that tens of thousands of such servers are at risk, and the lack of an operational fix from Microsoft is exacerbating the situation, forcing victims around the world to deal with the consequences on their own.
All important news is on the Izvestia channel in the MAX messenger.
Переведено сервисом «Яндекс Переводчик»