Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2026 GBAF Publications Ltd - All Rights Reserved. | Sitemap | Tags | Developed By eCorpIT

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Headlines > Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows
    Headlines

    Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows

    Published by Global Banking & Finance Review®

    Posted on July 22, 2025

    4 min read

    Last updated: January 22, 2026

    Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows - Headlines news and analysis from Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:securitycybersecuritytechnologyfinancial servicesinvestment

    Quick Summary

    Microsoft's SharePoint patch failed to fix a critical flaw, leading to global cyber espionage. Chinese hacking groups exploited the vulnerability, affecting over 8,000 servers.

    Table of Contents

    • Overview of SharePoint Security Issues
    • Details of the Vulnerability
    • Impact on Organizations
    • Response from Microsoft
    • Involvement of Cybersecurity Firms

    Microsoft's SharePoint Security Flaw: Incomplete Patch Revealed

    Overview of SharePoint Security Issues

    By James Pearson

    LONDON (Reuters) -A security patch released by Microsoft earlier this month failed to fully fix a critical flaw in the U.S. tech company's SharePoint server software that had been identified at a hacking competition in May, opening the door to a sweeping global cyber espionage operation, according to a timeline of events reviewed by Reuters.

    A Microsoft spokesperson confirmed on Tuesday that its initial solution did not work. The spokesperson added that Microsoft had released further patches that fixed the issue.

    Details of the Vulnerability

    It remains unclear who is behind the ongoing operation, which targeted around 100 organisations over the weekend and is expected to escalate as other hackers join the fray. Microsoft said in a blog post that two allegedly Chinese hacking groups, dubbed "Linen Typhoon" and "Violet Typhoon," were exploiting the vulnerabilities, along with another China-based hacking group.

    Impact on Organizations

    Microsoft and Alphabet's Google have said that China-linked hackers were likely behind the first wave of hacks.

    Response from Microsoft

    Chinese government-linked operatives are regularly implicated in cyberattacks, but Beijing routinely denies carrying out hacking operations. In an emailed statement, the Chinese embassy in Washington said China opposes all forms of cyberattacks, and "smearing others without solid evidence." 

    Involvement of Cybersecurity Firms

    The vulnerability that facilitated the attack was first identified in May at a hacking competition in Berlin organised by cybersecurity firm Trend Micro, which offered cash bounties for the discovery of computer bugs in popular software.

    It offered a $100,000 prize for "zero-day" exploits - which are called that because they leverage previously undisclosed digital weaknesses that could be used against SharePoint, Microsoft's flagship document management and collaboration platform.

    A researcher working for the cybersecurity arm of Viettel, a telecommunications firm operated by Vietnam's military, identified a SharePoint bug at the event, dubbed it "ToolShell" and demonstrated a method of exploiting it. 

    The researcher was awarded $100,000 for the discovery, according to a post on X by Trend Micro's "Zero Day Initiative."

    In a statement, Trend Micro said it was the responsibility of vendors participating in its competition to patch and disclose security flaws in "an effective and timely manner."

    "Patches will occasionally fail. This has happened with SharePoint in the past," the statement said.

    Microsoft said in a July 8 security update that it had identified the bug, listed it as a critical vulnerability, and released patches to fix it. 

    About 10 days later, however, cybersecurity firms started to notice an influx of malicious online activity targeting the same software the bug sought to exploit: SharePoint servers.

    "Threat actors subsequently developed exploits that appear to bypass these patches," British cybersecurity firm Sophos said in a blog post on Monday. 

    The pool of potential ToolShell targets remains vast.

    According to data from Shodan, a search engine that helps identify internet-linked equipment, over 8,000 servers online could theoretically have already been compromised by hackers.

    Those servers include major industrial firms, banks, auditors, healthcare companies, and several U.S. state-level and international government entities. 

    The Shadowserver Foundation, which scans the internet for potential digital vulnerabilities, put the number at a little more than 9,000, while cautioning that the figure was a minimum. 

    It said most of those affected were in the United States and Germany, and the victims included government organisations.

    Germany's federal office for information security, BSI, said on Tuesday it had found SharePoint servers within government networks that were vulnerable to the ToolShell attack but none had been compromised.

    (Reporting by James Pearson; Additional reporting by Raphael Satter and AJ Vicens; Editing by Joe Bavier and Rod Nickel)

    Key Takeaways

    • •Microsoft's initial patch for SharePoint was ineffective.
    • •Chinese hacking groups exploited the SharePoint vulnerability.
    • •The flaw was identified at a hacking competition in May.
    • •Over 8,000 servers potentially compromised globally.
    • •Cybersecurity firms noticed increased malicious activity.

    Frequently Asked Questions about Microsoft knew of SharePoint security flaw but failed to effectively patch it, timeline shows

    1What is a security flaw?

    A security flaw is a weakness in a system that can be exploited by attackers to gain unauthorized access or cause harm.

    2What is cybersecurity?

    Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks aimed at accessing, changing, or destroying sensitive information.

    3What is a vulnerability in software?

    A vulnerability in software is a flaw or weakness that can be exploited by attackers to compromise the security of the system.

    4What is a patch in software development?

    A patch is a piece of software designed to update or fix issues in a computer program, often addressing security vulnerabilities.

    More from Headlines

    Explore more articles in the Headlines category

    Image for Hungary's opposition Tisza promises wealth tax, euro adoption in election programme
    Hungary's opposition Tisza promises wealth tax, euro adoption in election programme
    Image for Thousands protest in Berlin in solidarity with Iranian uprisings
    Thousands protest in Berlin in solidarity with Iranian uprisings
    Image for Farmers report 'catastrophic' damage to crops as Storm Marta hits Spain and Portugal
    Farmers report 'catastrophic' damage to crops as Storm Marta hits Spain and Portugal
    Image for France opens probe against ex-culture minister lang after Epstein file dump
    France opens probe against ex-culture minister lang after Epstein file dump
    Image for If US attacks, Iran says it will strike US bases in the region
    If US attacks, Iran says it will strike US bases in the region
    Image for Suspected saboteurs hit Italian rail network near Bologna, police say
    Suspected saboteurs hit Italian rail network near Bologna, police say
    Image for Olympics-Protesters in Milan denounce impact of Games on environment
    Olympics-Protesters in Milan denounce impact of Games on environment
    Image for Olympics-Biathlon-Winter Games bring tourism boost to biathlon hotbed of northern Italy
    Olympics-Biathlon-Winter Games bring tourism boost to biathlon hotbed of northern Italy
    Image for US pushes Russia and Ukraine to end war by summer, Zelenskiy says
    US pushes Russia and Ukraine to end war by summer, Zelenskiy says
    Image for Russia to interrogate two suspects over attempted killing of general, report says
    Russia to interrogate two suspects over attempted killing of general, report says
    Image for Russia launches massive attack on Ukraine's energy system, Zelenskiy says
    Russia launches massive attack on Ukraine's energy system, Zelenskiy says
    Image for Ukraine backs Pope's call for Olympic truce in war with Russia
    Ukraine backs Pope's call for Olympic truce in war with Russia
    View All Headlines Posts
    Previous Headlines PostDavid Broadbent appointed CEO of Europe's SES Space & Defense
    Next Headlines PostSpain proposes declassifying secret Franco era files