Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Headlines > Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows
    Headlines

    Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows

    Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows

    Published by Global Banking and Finance Review

    Posted on July 22, 2025

    Featured image for article about Headlines

    By James Pearson

    LONDON (Reuters) -A security patch released by Microsoft earlier this month failed to fully fix a critical flaw in the U.S. tech company's SharePoint server software that had been identified at a hacking competition in May, opening the door to a sweeping global cyber espionage operation, according to a timeline of events reviewed by Reuters.

    A Microsoft spokesperson confirmed on Tuesday that its initial solution did not work. The spokesperson added that Microsoft had released further patches that fixed the issue.

    It remains unclear who is behind the ongoing operation, which targeted around 100 organisations over the weekend and is expected to escalate as other hackers join the fray. Microsoft said in a blog post that two allegedly Chinese hacking groups, dubbed "Linen Typhoon" and "Violet Typhoon," were exploiting the vulnerabilities, along with another China-based hacking group.

    Microsoft and Alphabet's Google have said that China-linked hackers were likely behind the first wave of hacks.

    Chinese government-linked operatives are regularly implicated in cyberattacks, but Beijing routinely denies carrying out hacking operations. In an emailed statement, the Chinese embassy in Washington said China opposes all forms of cyberattacks, and "smearing others without solid evidence." 

    The vulnerability that facilitated the attack was first identified in May at a hacking competition in Berlin organised by cybersecurity firm Trend Micro, which offered cash bounties for the discovery of computer bugs in popular software.

    It offered a $100,000 prize for "zero-day" exploits - which are called that because they leverage previously undisclosed digital weaknesses that could be used against SharePoint, Microsoft's flagship document management and collaboration platform.

    A researcher working for the cybersecurity arm of Viettel, a telecommunications firm operated by Vietnam's military, identified a SharePoint bug at the event, dubbed it "ToolShell" and demonstrated a method of exploiting it. 

    The researcher was awarded $100,000 for the discovery, according to a post on X by Trend Micro's "Zero Day Initiative."

    In a statement, Trend Micro said it was the responsibility of vendors participating in its competition to patch and disclose security flaws in "an effective and timely manner."

    "Patches will occasionally fail. This has happened with SharePoint in the past," the statement said.

    Microsoft said in a July 8 security update that it had identified the bug, listed it as a critical vulnerability, and released patches to fix it. 

    About 10 days later, however, cybersecurity firms started to notice an influx of malicious online activity targeting the same software the bug sought to exploit: SharePoint servers.

    "Threat actors subsequently developed exploits that appear to bypass these patches," British cybersecurity firm Sophos said in a blog post on Monday. 

    The pool of potential ToolShell targets remains vast.

    According to data from Shodan, a search engine that helps identify internet-linked equipment, over 8,000 servers online could theoretically have already been compromised by hackers.

    Those servers include major industrial firms, banks, auditors, healthcare companies, and several U.S. state-level and international government entities. 

    The Shadowserver Foundation, which scans the internet for potential digital vulnerabilities, put the number at a little more than 9,000, while cautioning that the figure was a minimum. 

    It said most of those affected were in the United States and Germany, and the victims included government organisations.

    Germany's federal office for information security, BSI, said on Tuesday it had found SharePoint servers within government networks that were vulnerable to the ToolShell attack but none had been compromised.

    (Reporting by James Pearson; Additional reporting by Raphael Satter and AJ Vicens; Editing by Joe Bavier and Rod Nickel)

    Related Posts
    Bangladesh tightens security after youth leader’s killing as media attacks stoke unrest fears
    Bangladesh tightens security after youth leader’s killing as media attacks stoke unrest fears
    Ukraine says it hit Russian oil rig, patrol ship in Caspian Sea
    Ukraine says it hit Russian oil rig, patrol ship in Caspian Sea
    US, Russian officials to meet in Florida for more Ukraine talks
    US, Russian officials to meet in Florida for more Ukraine talks
    US hits ISIS in Syria with large retaliatory strikes, officials say
    US hits ISIS in Syria with large retaliatory strikes, officials say
    Australia PM says Jewish community 'completely unbreakable' after Bondi attack
    Australia PM says Jewish community 'completely unbreakable' after Bondi attack
    Russia's Dmitriev heading for US to meet Witkoff, Kushner, source says
    Russia's Dmitriev heading for US to meet Witkoff, Kushner, source says
    IMF welcomes EU's 90 billion euro loan to Ukraine, more work to be done
    IMF welcomes EU's 90 billion euro loan to Ukraine, more work to be done
    Israeli attack on school shelter in Gaza City kills 5 Palestinians, hospital chief says
    Israeli attack on school shelter in Gaza City kills 5 Palestinians, hospital chief says
    Russian missiles attack port near Ukraine's Odesa, kill seven, officials say
    Russian missiles attack port near Ukraine's Odesa, kill seven, officials say
    Rubio says new governance bodies for Gaza will be in place soon, followed by international force
    Rubio says new governance bodies for Gaza will be in place soon, followed by international force
    Musk wins appeal that restores 2018 Tesla pay deal now worth about $139 billion
    Musk wins appeal that restores 2018 Tesla pay deal now worth about $139 billion
    US intelligence indicates Putin's war aims in Ukraine are unchanged
    US intelligence indicates Putin's war aims in Ukraine are unchanged

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Headlines PostDavid Broadbent appointed CEO of Europe's SES Space & Defense
    Next Headlines PostSpain proposes declassifying secret Franco era files

    More from Headlines

    Explore more articles in the Headlines category

    Bondi attack suspects kept to themselves during Philippines stay, hotel staffer recalls

    Bondi attack suspects kept to themselves during Philippines stay, hotel staffer recalls

    UK author David Walliams dropped by publisher after harassment allegations

    UK author David Walliams dropped by publisher after harassment allegations

    Germany removes dividend ban for Uniper, paving way for IPO

    Germany removes dividend ban for Uniper, paving way for IPO

    Golden Goose gets new majority owner as China's HSG buys stake from Permira

    Golden Goose gets new majority owner as China's HSG buys stake from Permira

    Rubio says not concerned about escalation with Russia over Venezuela

    Rubio says not concerned about escalation with Russia over Venezuela

    French government to appeal court ruling on Shein

    French government to appeal court ruling on Shein

    Rome to charge tourists to get close to the famed Trevi Fountain

    Rome to charge tourists to get close to the famed Trevi Fountain

    Court in Brazil's Minas Gerais slaps down Nestle copyright lawsuit

    Court in Brazil's Minas Gerais slaps down Nestle copyright lawsuit

    German court jails man for drugging, raping wife, posting assaults online

    German court jails man for drugging, raping wife, posting assaults online

    Rubio says progress has been made in talks to end war in Ukraine, but still a ways to go

    Rubio says progress has been made in talks to end war in Ukraine, but still a ways to go

    UniCredit issues its first tokenised structured note

    UniCredit issues its first tokenised structured note

    Ukraine starts new round of talks with US, Kyiv negotiator says

    Ukraine starts new round of talks with US, Kyiv negotiator says

    View All Headlines Posts