China has accused US intelligence agencies of exploiting a Microsoft Exchange zero-day exploit to steal defense-related data and take over more than 50 devices belonging to a "major Chinese military enterprise" for nearly a year. In a Thursday alert, the National Computer Network Emergency Response Technical Team / Coordination Center of China (CNCERT/CC), a group which claims that it is non-governmental, said American cyberattacks against Chinese high-tech, defense-related universities, research institutes, and enterprises "have become more targeted and their methods, more covert." These data-stealing campaigns pose "a serious threat to the scientific research and production security of China's defense and defense industries, and even to national security," the alert continues. The US National Security Agency did not immediately respond to The Register's inquiries. CNCERT/CC's claims about American spies infiltrating military and defense-related organizations follow several recent allegations from the US about Chinese snooping activity. Last week, US-based security firms including Microsoft blamed recent SharePoint zero-day attacks on several Chinese groups, including at least two Beijing-backed snooping and data stealing crews, and a China-based ransomware gang. And earlier this week, SentinelLabs' security researchers uncovered more than a dozen patents for offensive cybersecurity tools filed by Chinese companies allegedly tied to Beijing's Silk Typhoon espionage crew. The...
China says US spies exploited Microsoft Exchange zero-day to steal military info
The Register
·Jessica Lyons
·Published Aug 1, 2025
·Updated
Affected Software
1 affected component
Microsoft Exchange