SharePoint MAPP leak investigation visual with Microsoft servers

Microsoft probes SharePoint MAPP leak in global breach

IntroductionOn July 25, 2025, Microsoft disclosed it is investigating potential leaks in its Microsoft Active Protections Program (MAPP), after China-linked threat groups used details to exploit the ‘ToolShell’ SharePoint vulnerability even after official patches. Background: SharePoint & ToolShell Vulnerability Discoverer at Viettel Cybersecurity reported ‘ToolShell’ in Berlin’s hacking contest. Microsoft patched it on July 8,…

SharePoint zero-day breach warning sign on server room background

Major SharePoint Zero‑Day Breach Hits ~100 Organisations

Introduction On July 21, 2025, cybersecurity researchers revealed a widespread zero-day vulnerability in Microsoft SharePoint, which has already been exploited to infiltrate at least 100 organisations worldwide, including U.S. and U.K. government agencies. This critical security flaw, which Microsoft is racing to patch, highlights once again the increasing sophistication and urgency of protecting enterprise collaboration…