23/07/2025
🇺🇸The US National Nuclear Security Administration (NNSA), responsible for America's nuclear arsenal, has fallen victim to a cyberattack exploiting vulnerabilities in Microsoft SharePoint software. The breach, which is part of the US Department of Energy, has raised serious concerns about national security and the resilience of government infrastructure against sophisticated cyberattacks.
*Key Details of the Breach:*
- *Method*: Hackers exploited zero-day vulnerabilities in Microsoft SharePoint servers, specifically CVE-2025-49770, to gain remote access and steal credentials.
- *Scope*: Over 100 organizations worldwide were affected, including government agencies, energy companies, universities, and consulting firms across 10 countries.
- *Attributed to*: Chinese state-sponsored hacking groups, namely Linen Typhoon, Violet Typhoon, and Storm-2603, with Microsoft having "medium confidence" in the attribution.
- *Impact*: No sensitive or classified information is believed to have been compromised, but the incident highlights the ongoing threat posed by Beijing-backed cyber espionage operations ¹ ².
*Response and Mitigation:*
- Microsoft has released security patches for all affected SharePoint versions and urged organizations to apply them immediately.
- The Cybersecurity and Infrastructure Security Agency (CISA) has added the exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, emphasizing the need for prompt patching.
- CISA and Microsoft are working closely with federal agencies and international partners to share threat intelligence and technical guidance for detecting and mitigating the campaign