Close Menu
Core Bulletin

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    People in the US: have you been affected by interest resuming on student loan debt under the Save plan? | US student debt

    August 9, 2025

    Sam Altman says he doesn’t think about Elon Musk that much

    August 9, 2025

    Ordinary Decent Criminal review – Mark Thomas powers through tense prison drama | Edinburgh festival 2025

    August 9, 2025
    Facebook X (Twitter) Instagram
    Core BulletinCore Bulletin
    Trending
    • People in the US: have you been affected by interest resuming on student loan debt under the Save plan? | US student debt
    • Sam Altman says he doesn’t think about Elon Musk that much
    • Ordinary Decent Criminal review – Mark Thomas powers through tense prison drama | Edinburgh festival 2025
    • Tim Dowling: my wife takes the dog to be spayed. It’s best I don’t go with her | Pets
    • Eddie Howe accepts Alexander Isak’s future at Newcastle is out of his control | Newcastle United
    • Who are Premier League title favourites: Liverpool, Arsenal, Man City, Utd? | Football News
    • Most foreign criminals convicted in UK to be deported immediately under new plans | Prisons and probation
    • ‘You have to ruffle feathers’: a history of controversial jeans adverts | Jeans
    Saturday, August 9
    • Home
    • Business
    • Health
    • Lifestyle
    • Politics
    • Science
    • Sports
    • Travel
    • World
    • Technology
    • Entertainment
    Core Bulletin
    Home»Business»US nuclear weapons agency ‘among 400 organisations breached by Chinese hackers’ | Microsoft
    Business

    US nuclear weapons agency ‘among 400 organisations breached by Chinese hackers’ | Microsoft

    By Liam PorterJuly 23, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
    US nuclear weapons agency ‘among 400 organisations breached by Chinese hackers’ | Microsoft
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft says Chinese “threat actors”, including state-sponsored hackers, have exploited security vulnerabilities in its SharePoint document-sharing servers, with research indicating that several hundred government agencies and organisations have been breached.

    Hackers have already breached 400 agencies, businesses and other groups, the Dutch cybersecurity company Eye Security said, adding: “We expect it may continue to rise as investigations progress.”

    The majority of the victims are in the US, it found, while Bloomberg reported that the US agency charged with overseeing nuclear weapons, the National Nuclear Security Administration, was among the victims.

    Microsoft said it had observed three groups – the Chinese state-backed Linen Typhoon and Violet Typhoon, and Storm-2603, which is believed to be China-based – using “newly disclosed security vulnerabilities” to target internet-facing servers hosting the platform.

    Its announcement came amid reports in the Financial Times that Amazon was shutting down its artificial intelligence lab in Shanghai, while the consultancy McKinsey has stopped its China business from taking on work related to AI amid worsening geopolitical tensions between Washington and Beijing.

    Microsoft and IBM have recently scaled back China-based research and development projects, as US officials are stepping up their scrutiny of US companies working in AI in China.

    Microsoft said in a blogpost that the vulnerabilities were in on-premises SharePoint servers, which are commonly used by companies, rather than in its cloud-based service.

    Many large organisations and businesses use SharePoint as a platform for storing documents and allowing colleagues to collaborate on them, and it is regarded as working well alongside other Microsoft products, including Office and Outlook.

    Microsoft said the attacks had begun as early as 7 July and that the hackers were trying to exploit vulnerabilities to “gain initial access to target organisations”.

    The vulnerabilities allow attackers to spoof authentication credentials and execute malicious code remotely on servers. Microsoft said it had observed attacks where the attackers had sent a request to a SharePoint server “enabling the theft of the key material”.

    Microsoft said it had released security updates and advised all users of on-premises SharePoint systems to install them. It warned that it assessed with “high confidence” that the hacking groups would continue to attack unpatched on-premises SharePoint systems.

    skip past newsletter promotion

    Sign up to Business Today

    Get set for the working day – we’ll point you to all the business news and analysis you need every morning

    Privacy Notice: Newsletters may contain info about charities, online ads, and content funded by outside parties. For more information see our Privacy Policy. We use Google reCaptcha to protect our website and the Google Privacy Policy and Terms of Service apply.

    after newsletter promotion

    Eye Security said in a press release that it had detected “unusual activity” on a customer’s on-premises SharePoint server on the evening of 18 July. It added that it had subsequently scanned more than 8,000 publicly accessible SharePoint servers around the world and had “identified dozens of compromised systems, confirming that attackers are conducting a coordinated mass exploitation campaign”.

    Microsoft said Linen Typhoon had been “focused on stealing intellectual property, primarily targeting organisations related to government, defence, strategic planning, and human rights” since 2012.

    It added that since 2015 Violet Typhoon had been “dedicated to espionage, primarily targeting former government and military personnel, non-governmental organisations, thinktanks, higher education, digital and print media, financial and health related sectors in the United States, Europe, and east Asia”.

    Microsoft said it had “medium confidence” that the third group, Storm-2603, was based in China, but said it had not established links between the group and other Chinese threat actors. It warned that “additional actors” might also target on-premises SharePoint systems to exploit their vulnerabilities if its security updates were not installed.

    Agency among breached Chinese hackers Microsoft nuclear organisations weapons
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Liam Porter
    • Website

    Liam Porter is a seasoned news writer at Core Bulletin, specializing in breaking news, technology, and business insights. With a background in investigative journalism, Liam brings clarity and depth to every piece he writes.

    Related Posts

    People in the US: have you been affected by interest resuming on student loan debt under the Save plan? | US student debt

    August 9, 2025

    ‘You have to ruffle feathers’: a history of controversial jeans adverts | Jeans

    August 9, 2025

    ‘Erasure of years of work’: outcry as White House moves to open Arctic reserve to oil and gas drilling | Alaska

    August 9, 2025

    Trump-backed World Liberty proposes $1.5bn crypto holder, Bloomberg News reports | Cryptocurrencies

    August 9, 2025

    Women call out ‘creepy’ experiences on Vinted as trolls and image thieves target site | Sexual harassment

    August 9, 2025

    Trump Media to broadcast GB News on US streaming platform Truth+ | GB News

    August 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Medium Rectangle Ad
    Don't Miss
    Business

    People in the US: have you been affected by interest resuming on student loan debt under the Save plan? | US student debt

    August 9, 2025

    Under the Biden administration, about 8 million people enrolled in a 2023 income-driven repayment plan…

    Sam Altman says he doesn’t think about Elon Musk that much

    August 9, 2025

    Ordinary Decent Criminal review – Mark Thomas powers through tense prison drama | Edinburgh festival 2025

    August 9, 2025

    Tim Dowling: my wife takes the dog to be spayed. It’s best I don’t go with her | Pets

    August 9, 2025
    Our Picks

    Reform council confirms ‘patriotic’ flag policy

    July 4, 2025

    Trump references bankers with antisemitic slur in Iowa speech to mark megabill’s passage – as it happened | Donald Trump

    July 4, 2025

    West Indies v Australia: Tourists bowled out for 286 in Grenada Test

    July 4, 2025

    Beards may be dirtier than toilets – but all men should grow one | Polly Hudson

    July 4, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Medium Rectangle Ad
    About Us

    Welcome to Core Bulletin — your go-to source for reliable news, breaking stories, and thoughtful analysis covering a wide range of topics from around the world. Our mission is to inform, engage, and inspire our readers with accurate reporting and fresh perspectives.

    Our Picks

    People in the US: have you been affected by interest resuming on student loan debt under the Save plan? | US student debt

    August 9, 2025

    Sam Altman says he doesn’t think about Elon Musk that much

    August 9, 2025
    Recent Posts
    • People in the US: have you been affected by interest resuming on student loan debt under the Save plan? | US student debt
    • Sam Altman says he doesn’t think about Elon Musk that much
    • Ordinary Decent Criminal review – Mark Thomas powers through tense prison drama | Edinburgh festival 2025
    • Tim Dowling: my wife takes the dog to be spayed. It’s best I don’t go with her | Pets
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 Core Bulletin. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.