Microsoft Probes Potential MAPP Leak Following SharePoint Breaches Linked to Chinese State Groups

Key Takeaways:

  • Microsoft is investigating whether vulnerability details shared via its Microsoft Active Protections Program (MAPP) were leaked and used by China-linked hackers to exploit SharePoint flaws.
  • Exploitation of SharePoint zero-day vulnerabilities reportedly began within hours of MAPP alerts being issued to trusted partners, raising concerns of an insider leak.
  • Over 400 organizations—including U.S. federal agencies like the National Nuclear Security Administration and Department of Education—have been affected.
  • Microsoft attributes the intrusions to Chinese-affiliated groups Linen Typhoon, Violet Typhoon, and Storm-2603, though China has denied involvement.
  • Security researchers and officials warn that Microsoft’s initial patch was incomplete, leaving systems vulnerable even after administrators applied fixes.

Microsoft is facing renewed scrutiny after opening a formal investigation into whether a vulnerability disclosure shared through its Microsoft Active Protections Program (MAPP) was leaked and used by Chinese-aligned hackers to exploit zero-day flaws in SharePoint. The ongoing probe has reignited debate about the risks of sharing pre-patch vulnerability data—even with trusted security vendors—and has exposed gaps in Microsoft’s patching and alerting infrastructure.

In other recent and related news, New York added cyber rules to secure water systems, CISA and the FBI warned about infrastructure attacks, NY State Department of Health issued a cybersecurity alert, NY’s new cybersecurity law signaled a shift for municipal IT and Hochul signs cybersecurity bill to shield New York communities.

The investigation centers on the timeline surrounding a critical set of SharePoint vulnerabilities disclosed in late June 2025. According to multiple reports, members of MAPP received early technical details about the flaws between June 24 and July 7. However, exploitation in the wild reportedly began as early as July 7, the same day some alerts were issued—suggesting that attackers may have accessed the vulnerability data through an unauthorized channel.

While Microsoft has not confirmed a breach of MAPP itself, the company is examining whether one or more of its partners may have mishandled or leaked sensitive technical details. This would not be the first time concerns were raised about the program: in 2012, a Chinese security vendor was removed from MAPP after leaking details of an Exchange vulnerability that was later used in a widespread attack.

Microsoft launched MAPP in 2008 as a way to give vetted security vendors and partners early access to vulnerability information so they could prepare detection signatures and defenses before public disclosure. In theory, this helps defenders stay ahead. But if attackers infiltrate the program—or if a partner leaks data—MAPP can serve as an early warning system not just for defenders, but for adversaries.

This concern is now at the center of the SharePoint breach investigation. Microsoft disclosed four critical vulnerabilities—CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771—all affecting SharePoint Server versions widely used in both public and private sectors. The company believes three Chinese state-affiliated hacking groups—Linen Typhoon, Violet Typhoon, and Storm-2603—are responsible for exploiting the flaws.

According to Microsoft’s July 22 blog post, the attackers used the vulnerabilities to steal cryptographic machine keys and compromise authentication tokens. This allowed them to impersonate admin-level accounts, exfiltrate sensitive data, and maintain persistent access to servers even after patches were deployed. The exploit chains reportedly bypassed user-level security and operated at the system level.

The fallout has been wide-reaching. Security researchers estimate more than 400 organizations have been affected, including U.S. federal agencies like the Department of Education and the National Nuclear Security Administration. Other victims reportedly include state-level government offices, regional education systems, and large enterprises across the energy and financial sectors. Microsoft has not disclosed the full list of victims but confirmed that attackers targeted organizations using on-premises SharePoint instances rather than cloud-hosted environments like Microsoft 365.

Security analysts have noted that Microsoft’s initial patch, released July 20, did not fully resolve the issues. Researchers from Palo Alto’s Unit 42 and other leading threat intel firms confirmed that patched systems were still being compromised in the days following release. The root cause appears to be a mismatch between patch design and real-world implementation, leaving servers open to token forgery and privilege escalation. Microsoft has since updated its guidance, recommending organizations rotate machine keys, review authentication logs, and enable telemetry features like AMSI and Defender Antivirus.

The implications for Microsoft’s vulnerability disclosure practices are serious. MAPP is a foundational component of the company’s responsible disclosure model. If it is found that a leak from within MAPP enabled the attacks, Microsoft may need to reevaluate its selection, auditing, and monitoring of participants.

Critics argue that the SharePoint incident exposes broader structural risks. As cyberattacks grow more sophisticated and state-affiliated groups use zero-day exploits in hybrid warfare and espionage, the time between vulnerability disclosure and active exploitation has narrowed. In many cases, it is now a matter of hours, not days. That compresses the window available to defenders and puts even well-managed systems at risk.

China has denied any involvement in the incident. In a statement issued through its foreign ministry, Beijing accused Microsoft of making “politically motivated” claims without presenting evidence. China called for a “scientific and evidence-based investigation,” asserting that accusations of state-sponsored cyber activity are often used to deflect from internal failures in patching and security hygiene.

Still, U.S. officials remain concerned. Some have suggested that Congress may seek briefings on the incident, particularly as critical infrastructure and sensitive federal agencies were affected. Analysts expect further inquiry into Microsoft’s handling of the disclosure process and whether the company’s security architecture adequately protects its own threat-sharing programs.

For enterprise IT leaders, the incident underscores the need for layered defense strategies and proactive threat monitoring. While patching remains essential, so does maintaining access logs, rotating sensitive keys, and ensuring telemetry systems are in place to detect anomalous behavior. Organizations still running on-premise SharePoint installations—especially those without strict segmentation or zero trust policies—face increased risk in the wake of these developments.

As the investigation continues, Microsoft has pledged to enhance transparency and coordinate with government agencies and partners to mitigate impact. Whether that includes reforms to MAPP or changes to how pre-disclosure data is managed remains to be seen.

In the meantime, the SharePoint incident is a potent reminder that early warning systems, if misused, can become attack vectors themselves. The balance between empowering defenders and avoiding adversary exploitation has never been more delicate.

Learn how AI Agents can supercharge your company’s profits and productivity at TMC’s AI Agent Event, Sept 29-30, 2025 in DC.

If you liked this post, you’ll love one of the the leading global business communications and technology events since 1999, the ITEXPO #TECHSUPERSHOW, Feb 10-12, 2026 Fort Lauderdale, Florida.

Don’t forget the collocated MSP Expo – just for managed service providers!

Aside from his role as CEO of TMC and chairman of ITEXPO #TECHSUPERSHOW Feb 10-12, 2026, Rich Tehrani is CEO of RT Advisors and a Registered Representative (investment banker) with and offering securities through Four Points Capital Partners LLC (Four Points) (Member FINRA/SIPC). He handles capital/debt raises as well as M&A. RT Advisors is not owned by Four Points.

The above is not an endorsement or recommendation to buy/sell any security or sector mentioned. No companies mentioned above are current or past clients of RT Advisors.

The views and opinions expressed above are those of the participants. While believed to be reliable, the information has not been independently verified for accuracy. Any broad, general statements made herein are provided for context only and should not be construed as exhaustive or universally applicable.

Portions of this article may have been developed with the assistance of artificial intelligence, which may have contributed to ideation, content generation, factual review, or editing


 

Loading
Share via
Copy link
Powered by Social Snap