Risk highlighted as Chinese hackers hit Microsoft

Microsoft’s success at making its software commonplace in offices and homes also makes it a prime target for hackers out to steal money or information. (Reuters)
Short Url
Updated 25 July 2025
Follow

Risk highlighted as Chinese hackers hit Microsoft

  • Dutch startup Eye Security warned of online attacks targeting SharePoint file-sharing servers
  • Targets included government organizations in Europe, the Middle East and the US — among them the US nuclear weapons agency

PARIS : Software giant Microsoft is at the center of cybersecurity storm after China-linked hackers exploited flaws in SharePoint servers to target hundreds of organizations.
While such cyberattacks are not new, the scale of the onslaught and the speed with which the hackers took advantage of freshly discovered vulnerabilities is fueling concern.
Dutch startup Eye Security warned Saturday of online attacks targeting SharePoint file-sharing servers, with Microsoft quick to confirm the report and release patches to protect systems.
The vulnerability allowed hackers to retrieve credentials and then access SharePoint servers kept at users’ facilities, according to Microsoft.
Cloud-based SharePoint software was safe from the problem, the company said.

Eye Security determined that more than 400 computer systems were compromised by hackers during waves of attacks.
Targets included government organizations in Europe, the Middle East and the United States — among them the US nuclear weapons agency, media reports indicated.
“On-premises SharePoint deployments — particularly within government, schools, health care and large enterprise companies — are at immediate risk,” cybersecurity firm Palo Alto Networks warned in a note.
Microsoft has not disclosed the number of victims in the attacks.
SharePoint had more than 200 million active users as of 2020, according to the most recent figures available from Microsoft.

Microsoft has attributed the cyberattacks to groups backed by China.
The culprits are believed to include Chinese state actors known as Linen Typhoon and Violet Typhoon along with a group called Storm-2603 which “is considered with moderate confidence to be a threat actor based in China.”
The Typhoon groups have been active for a decade or more, and are known for intellectual property theft as well as espionage, according to Microsoft.
Less was known about Storm-2603 and its motives.
“Investigations into other actors also using these exploits are ongoing,” Microsoft said, urging users to patch SharePoint servers to avoid becoming hacking victims.
Cybersecurity specialist Damien Bancal noted in a recent blog post that he found “ready-to-use exploit code” for the vulnerability at a popular website.

The assault on SharePoint servers is the latest in a series of sophisticated attacks carried out by state-sponsored groups against “the Microsoft ecosystem,” according to Bancal.
In 2021, attacks by a Chinese hacker group known as Silk Typhoon compromised tens of thousands of email servers using Microsft Exchange software.
Microsoft’s success at making its software commonplace in offices and homes also makes it a prime target for hackers out to steal money or information.
Microsoft software can hold sensitive and valuable information.
“It’s not Microsoft that is being targeted, it’s its customers,” said Shane Barney, head of information security at US-based Keeper.
Targeting Microsoft programs is a means to an end, and tomorrow it could be software from another company, said Rodrigue Le Bayon, head of Orange Cyberdefense computer emergency response team.

China is not the only nation backing hacker operations as countries around the world hone cyber capabilities, according to Le Bayon.
Nevertheless, China is repeatedly singled out by companies and goverments hit by hacks.
Western countries have accused hacker groups allegedly supported by China of conducting a global cyber espionage campaign against figures critical of Beijing, democratic institutions, and companies in various sensitive sectors.


FIFA boss ‘very reassured’ about World Cup in Mexico despite violence

Updated 2 sec ago
Follow

FIFA boss ‘very reassured’ about World Cup in Mexico despite violence

  • Mexico is one of the three host countries for the June 11-July 19 World Cup, along with the United States and Canada
BARRANQUILLA: FIFA boss Gianni Infantino told AFP on Tuesday he was “very reassured” about Mexico’s hosting of games in the football World Cup, in his first comments on the violence triggered by the killing of a drug cartel leader.
“Very reassured, everything’s good. It’s going to be spectacular,” Infantino said in the Colombian city of Barranquilla, two days after cartel members went on a rampage — including in host city Guadalajara — over the army’s killing of their leader Nemesio “El Mencho” Oseguera.
Mexico is one of the three host countries for the June 11-July 19 World Cup, along with the United States and Canada.
The country as a whole, but particularly Guadalajara, was shaken by the violence that followed the killing of the leader of the powerful Jalisco New Generation Cartel (CJNG).
At least 74 people were killed during the operation to capture him at a ranch near Guadalajara and subsequent clashes between the security forces and suspected cartel members.
Only one was a civilian, according to the government, but residents and tourists alike were left scurrying for cover as cartel gunmen blocked roads in 20 of Mexico’s 32 states and torched vehicles and businesses.
- ‘No risk’ to football fans -
“It feels like we’re in a war zone,” Javier Perez, a 41-year-old engineer, told AFP on Tuesday in the parking lot of a grocery store replete with burnt-out cars in the Jalisco tourist resort of Puerto Vallarta.
The images of anarchy and violence were beamed around the world less than four months before the start of the World Cup, while FIFA on Monday refused to comment.
Infantino spoke to AFP at a Colombian Football Federation event.
However, Infantino’s optimism was not reflected by the Portuguese Football Federation, who cast doubt on whether their team would play a friendly on March 29 in Mexico City.
The federation said it was “closely monitoring the delicate situation currently unfolding in Mexico.”
It added that the safety of players, coaches and supporters was a top priority and security considerations would be the deciding factor.
Mexico national team coach Javier Aguirre was more upbeat, declaring: “All is going ahead as planned.”
Earlier, Mexican President Claudia Sheinbaum assured that there was “no risk” to World Cup fans and said the situation was “gradually returning to normal.”
Guadalajara, the capital of Jalisco state, will host four group-stage matches.
Mexico City and the northeastern city of Monterrey will also host games. Both cities were spared by the recent unrest.
In addition to the four matches, including one of the most anticipated of the first round between Uruguay and Spain, Guadalajara will co-host with Monterrey the playoff tournament that will determine the last two teams to qualify for the World Cup at the end of March.
Jalisco Governor Pablo Lemus ruled out the prospect of Guadalajara being dropped from the tournament over security concerns, saying there was “absolutely no risk” of a change in the line-up.
All eyes will be on the central state of Queretaro on Wednesday, when Mexico meets Iceland for a friendly.
A first-division game was suspended on Sunday in Queretaro over the violence.
- Car manufacturing affected -
Oseguera was one of the most-wanted men in the United States and Mexico. He had a $15 million US bounty on his head.
Oseguera was a founding member of CJNG, which was formed in 2009 and grew into one of the biggest, most violent drug cartels in Mexico, overtaking the Sinaloa cartel of jailed kingpin Joaquin “El Chapo” Guzman.
Mexico confirmed that he was captured with the help of “complementary information” from US authorities, but insists no US forces took part in the raid.
As the fallout from the violence continued to reverberate nationwide, Japanese car manufacturer Honda announced that it had suspended activities at its assembly plant in Guadalajara.
“As a precautionary measure, our operations in our installations in Guadalajara were temporarily suspended on Monday, February 23,” Daniela Sanchez, a spokesperson for the car factory, told AFP, explaining that the automotive giant was currently “assessing the (security) situation.”
Mexico is a major automotive hub with several major manufacturers, including Ford, General Motors, BMW, and Audi, assembling vehicles in the country for the North American and European markets.