this post was submitted on 23 Jul 2025
185 points (97.0% liked)

Technology

73232 readers
4270 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Security researchers at Google and Microsoft say they have evidence that hackers backed by China are exploiting a zero-day bug in Microsoft SharePoint, as companies around the world scramble to patch the flaw.

The bug, known officially as CVE-2025-53770 and discovered last weekend, allows hackers to steal sensitive private keys from self-hosted versions of SharePoint, a software server widely used by companies and organizations to store and share internal documents. Once exploited, an attacker can use the bug to remotely plant malware and gain access to the files and data stored within, as well as gain access to other systems on the same network.

you are viewing a single comment's thread
view the rest of the comments
[–] drmoose@lemmy.world 30 points 4 days ago* (last edited 4 days ago) (1 children)

The attack exploits SharePoint vulnerabilities originally disclosed at a Berlin hacking competition in May, where a Vietnamese cybersecurity researcher received a $100,000 bounty for discovering the flaws. Reuters reported that Microsoft was allegedly informed of the vulnerabilities in May but failed to fully address them in an initial July patch

And

Several cybersecurity experts compared the SharePoint campaign to the 2021 Microsoft Exchange server attacks that compromised US government systems. Former FBI Cyber Unit deputy director Cynthia Kaiser warned that hackers "already in their systems may lie dormant for extended periods before operationalizing"

Just shows in what a poor position US is now. Allies discovered it, reported it, feds didn't prepare for it and Chinese are in. Incredible incompetence except for US allies that despite US' isolationism still care.

Source

[–] adespoton@lemmy.ca 11 points 4 days ago (1 children)

Yeah; allies still care because of the US military industrial complex. Compromising the US still compromises a large chunk of the world, making things even worse for everyone than the current US administration can do on its own.

[–] Squizzy@lemmy.world 2 points 1 day ago

And the rest of the world are not petulant children ready and willing to remove any semblance of cooperation, appreciation or decency.