Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Headlines
    3. >Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows
    Headlines

    Microsoft Knew of SharePoint Security Flaw but Failed to Effectively Patch It, Timeline Shows

    Published by Global Banking & Finance Review®

    Posted on July 22, 2025

    4 min read

    Last updated: January 22, 2026

    Add as preferred source on Google
    Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows - Headlines news and analysis from Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:securitycybersecuritytechnologyfinancial servicesinvestment

    Quick Summary

    Microsoft's SharePoint patch failed to fix a critical flaw, leading to global cyber espionage. Chinese hacking groups exploited the vulnerability, affecting over 8,000 servers.

    Microsoft's SharePoint Security Flaw: Incomplete Patch Revealed

    Overview of SharePoint Security Issues

    By James Pearson

    LONDON (Reuters) -A security patch released by Microsoft earlier this month failed to fully fix a critical flaw in the U.S. tech company's SharePoint server software that had been identified at a hacking competition in May, opening the door to a sweeping global cyber espionage operation, according to a timeline of events reviewed by Reuters.

    A Microsoft spokesperson confirmed on Tuesday that its initial solution did not work. The spokesperson added that Microsoft had released further patches that fixed the issue.

    Details of the Vulnerability

    It remains unclear who is behind the ongoing operation, which targeted around 100 organisations over the weekend and is expected to escalate as other hackers join the fray. Microsoft said in a blog post that two allegedly Chinese hacking groups, dubbed "Linen Typhoon" and "Violet Typhoon," were exploiting the vulnerabilities, along with another China-based hacking group.

    Impact on Organizations

    Microsoft and Alphabet's Google have said that China-linked hackers were likely behind the first wave of hacks.

    Response from Microsoft

    Chinese government-linked operatives are regularly implicated in cyberattacks, but Beijing routinely denies carrying out hacking operations. In an emailed statement, the Chinese embassy in Washington said China opposes all forms of cyberattacks, and "smearing others without solid evidence." 

    Involvement of Cybersecurity Firms

    The vulnerability that facilitated the attack was first identified in May at a hacking competition in Berlin organised by cybersecurity firm Trend Micro, which offered cash bounties for the discovery of computer bugs in popular software.

    It offered a $100,000 prize for "zero-day" exploits - which are called that because they leverage previously undisclosed digital weaknesses that could be used against SharePoint, Microsoft's flagship document management and collaboration platform.

    A researcher working for the cybersecurity arm of Viettel, a telecommunications firm operated by Vietnam's military, identified a SharePoint bug at the event, dubbed it "ToolShell" and demonstrated a method of exploiting it. 

    The researcher was awarded $100,000 for the discovery, according to a post on X by Trend Micro's "Zero Day Initiative."

    In a statement, Trend Micro said it was the responsibility of vendors participating in its competition to patch and disclose security flaws in "an effective and timely manner."

    "Patches will occasionally fail. This has happened with SharePoint in the past," the statement said.

    Microsoft said in a July 8 security update that it had identified the bug, listed it as a critical vulnerability, and released patches to fix it. 

    About 10 days later, however, cybersecurity firms started to notice an influx of malicious online activity targeting the same software the bug sought to exploit: SharePoint servers.

    "Threat actors subsequently developed exploits that appear to bypass these patches," British cybersecurity firm Sophos said in a blog post on Monday. 

    The pool of potential ToolShell targets remains vast.

    According to data from Shodan, a search engine that helps identify internet-linked equipment, over 8,000 servers online could theoretically have already been compromised by hackers.

    Those servers include major industrial firms, banks, auditors, healthcare companies, and several U.S. state-level and international government entities. 

    The Shadowserver Foundation, which scans the internet for potential digital vulnerabilities, put the number at a little more than 9,000, while cautioning that the figure was a minimum. 

    It said most of those affected were in the United States and Germany, and the victims included government organisations.

    Germany's federal office for information security, BSI, said on Tuesday it had found SharePoint servers within government networks that were vulnerable to the ToolShell attack but none had been compromised.

    (Reporting by James Pearson; Additional reporting by Raphael Satter and AJ Vicens; Editing by Joe Bavier and Rod Nickel)

    Table of Contents

    • Overview of SharePoint Security Issues
    • Details of the Vulnerability
    • Impact on Organizations
    • Response from Microsoft
    • Involvement of Cybersecurity Firms

    Key Takeaways

    • •Microsoft's initial patch for SharePoint was ineffective.
    • •Chinese hacking groups exploited the SharePoint vulnerability.
    • •The flaw was identified at a hacking competition in May.
    • •Over 8,000 servers potentially compromised globally.
    • •Cybersecurity firms noticed increased malicious activity.

    Frequently Asked Questions about Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows

    1What is a security flaw?

    A security flaw is a weakness in a system that can be exploited by attackers to gain unauthorized access or cause harm.

    2What is cybersecurity?

    Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks aimed at accessing, changing, or destroying sensitive information.

    3
    What is a vulnerability in software?

    A vulnerability in software is a flaw or weakness that can be exploited by attackers to compromise the security of the system.

    4What is a patch in software development?

    A patch is a piece of software designed to update or fix issues in a computer program, often addressing security vulnerabilities.

    More from Headlines

    Explore more articles in the Headlines category

    Image for Russia says it remains in contact with US on Ukraine settlement
    Russia Says It Remains in Contact With US on Ukraine Settlement
    Image for Putin allies Lukashenko and Kim meet in North Korea
    Putin Allies Lukashenko and Kim Meet in North Korea
    Image for Denmark's Frederiksen faces tough coalition talks to remain prime minister
    Denmark's Frederiksen Faces Tough Coalition Talks to Remain Prime Minister
    Image for UK police arrest two men over arson attack on Jewish community ambulances
    UK Police Arrest Two Men Over Arson Attack on Jewish Community Ambulances
    Image for Cricket-Bairstow joins Livingstone in criticising level of care in England set-up
    Cricket-Bairstow Joins Livingstone in Criticising Level of Care in England Set-Up
    Image for Mullally to be installed as first female Archbishop of Canterbury
    Mullally to Be Installed as First Female Archbishop of Canterbury
    Image for Cyprus seeks new security deal for UK bases, Telegraph reports
    Cyprus Seeks New Security Deal for UK Bases, Telegraph Reports
    Image for British army veteran completes record 100km Land Rover pull
    British Army Veteran Completes Record 100km Land Rover Pull
    Image for Pope Leo laments that Iran war 'getting worse and worse'
    Pope Leo Laments That Iran War 'getting Worse and Worse'
    Image for Denmark's left-wing bloc leads election but lacks majority, exit polls show
    Denmark's Left-Wing Bloc Leads Election but Lacks Majority, Exit Polls Show
    Image for Moldovan parliament backs energy state of emergency after power line put out of action
    Moldovan Parliament Backs Energy State of Emergency After Power Line Put Out of Action
    Image for US expected to send thousands more soldiers to Middle East, sources say
    US Expected to Send Thousands More Soldiers to Middle East, Sources Say
    View All Headlines Posts
    Previous Headlines PostDavid Broadbent Appointed CEO of Europe's Ses Space & Defense
    Next Headlines PostSpain Proposes Declassifying Secret Franco Era Files