Critical Microsoft vulnerability exploited by suspected China-backed groups prompts urgent cybersecurity warnings worldwide.
A Widespread and Growing Threat
A zero-day vulnerability in Microsoft SharePoint has triggered a wave of cyberattacks, with security researchers confirming that over 400 organizations have been compromised so far. The breach represents a sharp escalation from just days ago, when only a few dozen affected systems had been identified.
- The vulnerability, tracked as CVE-2025-53770, affects self-hosted SharePoint servers.
- It enables remote code execution, giving attackers potential access to sensitive files and entire corporate networks.
- Attacks began as early as July 7, according to forensic evidence.
High-Profile Targets: U.S. Nuclear Agency Among Those Hit
One of the most alarming confirmations came from Bloomberg, which reported that the National Nuclear Security Administration (NNSA) — the agency overseeing the U.S. nuclear weapons stockpile — was among those compromised.
- The Department of Energy confirmed a “minimal impact,” with only a few systems affected.
- Multiple U.S. government departments were also targeted in early attack waves.
- The implications are serious given SharePoint’s deep integration in many organizations’ document and knowledge-sharing infrastructure.
Who’s Behind the Attacks?
Both Google and Microsoft have attributed the initial wave of attacks to China-backed hacking groups. While China denies the accusations, both tech giants say the attackers are well-resourced and coordinated, consistent with nation-state tactics.
- Attribution is based on tools, techniques, and patterns matching known Chinese cyber espionage groups.
- Experts warn the exploit is now public knowledge, so criminal and state-affiliated groups worldwide may jump on the opportunity.
Why This Zero-Day Is Dangerous
As a zero-day vulnerability, the SharePoint bug was exploited before Microsoft could develop a patch, leaving organizations temporarily defenseless.
- Self-hosted SharePoint systems are often critical infrastructure, storing internal documentation, credentials, and project data.
- Exploiting CVE-2025-53770 gives attackers deep, persistent access to infected environments.
- The risk expands beyond SharePoint to other internal systems if lateral movement occurs.
Microsoft has since released patches for all affected SharePoint versions and urges all administrators to apply them immediately.
Global Security Community on High Alert
Eye Security, a Dutch firm that first identified the flaw, has been scanning the internet to detect impacted servers. Their count has grown rapidly, indicating many organizations remain vulnerable.
- Warnings have been issued by multiple cybersecurity agencies worldwide.
- Companies are urged to check whether they run on-premise SharePoint and verify patch implementation.
- Incident response teams should also look for signs of compromise dating back to early July.
Long-Term Fallout and Security Takeaways
The SharePoint breach underscores growing concerns over software supply chain vulnerabilities and delays in patching critical systems. Despite rapid patch development from Microsoft, lagging deployment has allowed attackers to gain a foothold in sensitive systems.
- Reinforces the need for zero-trust security architectures
- Highlights the risks of self-hosted enterprise software without proper monitoring
- Calls attention to the value of routine vulnerability scanning and rapid response protocols
With more hacker groups expected to exploit the bug, the number of compromised systems is likely to climb, increasing the urgency for organizations to respond swiftly.








