A critical vulnerability in Microsoft's popular SharePoint server software has resurfaced after the initial security update failed to fully patch vulnerable systems. The result? A new wave of cyber espionage affecting hundreds of organizations worldwide - from banks and industries to the military.

The bug, the patch and… the failure
Microsoft had acknowledged the problem in May, when researchers presented the “ToolShell” exploit at a hacking competition in Berlin, hosted by Trend Micro. The successful exploit offered $100,000 to the researcher who discovered it, but a patch attempt on July 8 proved insufficient.
See also: New vulnerability in 7-Zip allows system corruption
Within ten days of the patch, cybersecurity companies like Sophos recorded a massive resurgence of malicious activity targeting SharePoint servers. Attackers were able to bypass the initial fix and continue exploiting systems with alternative attack tools.
Who is behind the campaign?
Although Microsoft has not yet officially claimed responsibility, it said in a statement that the exploit was used by three Chinese APT groups, including the well-known “Linen Typhoon” and “Violet Typhoon”Google analysts have also made similar estimates.
The Chinese embassy in Washington denied any involvement, calling the reports unsubstantiated and defamatory, as is customary in similar cases.
Despite denials, it is a fact that the ToolShell exploit was used in breaches of critical US infrastructure, as revealed by Bloomberg. Among the targets was reportedly the US National Nuclear Security Administration, but there is no indication that classified data.
The extent of the threat – 9,000 vulnerable servers
According to the Shodan search engine and the Shadowserver Foundation , there are an estimated 8,000–9,000 SharePoint servers that remain potentially vulnerable, most of which are located in the United States and Germany .
See also: BIND 9 vulnerabilities expose organizations to DoS attacks
The list of potential targets includes banks, healthcare systems, government agencies, industries and international institutions. Germany's BSI, however, clarified that no active breaches were found in government networks, despite the fact that some servers were exposed.
Zero - day attacks and the patching challenge
The SharePoint–ToolShell highlights a perennial problem in cybersecurity: the ineffectiveness of patches, especially when they are applied late or without full testing.
Despite the best intentions, Microsoft admitted that the initial fix failed, coming back with a new patch. But in the meantime, the exploit has been used by APT groups in real attacks — highlighting how closely critical vulnerabilities need to be monitored, especially in widely used software like SharePoint.
Acritical battle for cyberspace
The strategic importance of collaboration software – such as SharePoint – makes it a prime target for cyberespionage. When a zero-day vulnerability is exploited by state-sponsored groups, even a modest delay in patching can have enormous operational and national consequences.

What should organizations do now?
Experts warn:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Apply the latest Microsoft security updates immediately
- Independently check the effectiveness of the patch.
- Monitor logs and systems for suspicious activity, especially around PowerShell or unusual API connections.
- Evaluate the use of Web Application Firewalls (WAFs) and EDR solutions with an emphasis on in-memory execution.
- Consider completely re-evaluating SharePoint deployments in high-risk environments.
See also: VMware fixed vulnerabilities used at Pwn2Own Berlin 2025
It's not enough to fix the bug – you have to prevent it
The ToolShell story is another chapter in the evolution of digital geopolitics. Technology is the new battlefield, and zero-day exploits are the weapons. When attacks come before patches — or worse, after inadequate patches — the cost is shifted from the developer to the user.
The answer is not simply technical, but strategic and intergovernmental: it requires rapid disclosure, transparency, cooperation and deterrence, because in a world where information is power, information security is a national interest.
Source: Reuters
