Security Stop-Press: Chinese Hackers Exploit SharePoint Flaws

Microsoft has confirmed that Chinese state-linked hackers are exploiting critical flaws in on-premises SharePoint servers to steal data and deploy ransomware.

The groups, known as Linen Typhoon, Violet Typhoon, and Storm-2603, are targeting government, defence, and business organisations by abusing spoofing and remote code execution vulnerabilities. Cloud-based SharePoint systems are not affected.

Victims have been reported across multiple sectors and countries, including the UK. Microsoft says the attacks allow hackers to steal credentials, disable security tools, and spread ransomware such as Warlock.

Storm-2603, a China-based group, has been observed using a malicious script called spinstall0.aspx to gain access and escalate privileges inside networks. Microsoft has warned that more attackers are likely to adopt these methods.

To stay secure, businesses using on-prem SharePoint must install Microsoft’s latest security updates, rotate ASP.NET machine keys, enable AMSI protection, and use advanced endpoint detection tools to block post-exploit activity.

Security Stop-Press: Cyber Criminals Exploit Trusted Platforms in LOTS Attacks

Cyber criminals are exploiting trusted services like Microsoft, Google, and DocuSign to deliver malware and phishing attacks.

Known as Living off Trusted Services (LOTS), this tactic allows them to evade detection by leveraging widely used platforms.

Mimecast’s H2 2024 Global Threat Intelligence Report flagged LOTS attacks as a growing concern, with over 5 billion threats detected. Attackers use CAPTCHAs to block security scans and host malicious payloads on cloud platforms.

By infiltrating third-party providers, cyber criminals gain deep access to networks, making detection difficult. Traditional security measures based on domain reputation and authentication often fail.

To defend against LOTS attacks, businesses should implement AI-driven threat detection, Zero Trust policies, enhanced email security, and user training to mitigate risks and prevent exploitation of trusted services.