Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Google’s Veo 3.1 Simply Made AI Filmmaking Sound—and Look—Uncomfortably Actual

    October 17, 2025

    North Korean Hackers Use EtherHiding to Cover Malware Inside Blockchain Good Contracts

    October 16, 2025

    Why the F5 Hack Created an ‘Imminent Menace’ for 1000’s of Networks

    October 16, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Microsoft Tapped China Engineers for SharePoint Assist
    AI Ethics & Regulation

    Microsoft Tapped China Engineers for SharePoint Assist

    Declan MurphyBy Declan MurphySeptember 5, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Microsoft Tapped China Engineers for SharePoint Assist
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    A brand new investigation has revealed that Microsoft relied on China-based engineers to supply technical assist and bug fixes for SharePoint, the identical collaboration software program that was not too long ago exploited by Chinese language state-sponsored hackers in a large cyberattack affecting a whole lot of organizations, together with delicate U.S. authorities businesses.

    Final month, Microsoft introduced that Chinese language hackers had efficiently exploited vulnerabilities in SharePoint to breach the pc techniques of quite a few corporations and authorities businesses, together with the Nationwide Nuclear Safety Administration and the Division of Homeland Safety.

    Nonetheless, what the corporate didn’t disclose in its announcement was that SharePoint assist has been dealt with by a China-based engineering group for years.

    In line with inside Microsoft work-tracking system screenshots reviewed by ProPublica, China-based workers had been not too long ago fixing bugs for SharePoint “OnPrem” – the on-premises model of the software program that was focused in final month’s assaults.

    This model refers to software program put in and operated on clients’ personal computer systems and servers, making it notably weak to direct manipulation.

    When confronted about this association, Microsoft defended its practices, stating that the China-based group “is supervised by a US-based engineer and topic to all safety necessities and supervisor code evaluation.”

    The corporate additionally introduced that “work is already underway to shift this work to a different location,” although no particular timeline was offered.

    Whereas it stays unclear whether or not Microsoft’s China-based employees performed any position within the SharePoint hack, cybersecurity specialists have persistently warned concerning the important safety dangers posed by permitting Chinese language personnel to carry out technical assist and upkeep on U.S. authorities techniques.

    The Broader Sample of Concern

    This revelation is an element of a bigger sample that has emerged concerning Microsoft’s reliance on overseas staff. ProPublica’s investigation discovered that for over a decade, Microsoft has trusted overseas staff – together with these based mostly in China – to take care of the Protection Division’s cloud techniques.

    The oversight of those overseas staff comes from U.S.-based personnel often known as “digital escorts,” who usually lack the superior technical experience essential to successfully monitor their overseas counterparts.

    The escort association was initially developed by Microsoft to fulfill Protection Division officers who had been involved about overseas workers and to satisfy necessities that folks dealing with delicate information be U.S. residents or everlasting residents.

    Regardless of these measures, the system has left extremely delicate info weak because of the technical talent hole between escorts and the overseas engineers they supervise.

    The revelations have prompted important authorities response. Protection Secretary Pete Hegseth launched a complete evaluation of tech corporations’ reliance on foreign-based engineers to assist the division.

    Moreover, Senators Tom Cotton (R-Arkansas) and Jeanne Shaheen (D-New Hampshire) have written a number of letters to Hegseth, citing ProPublica’s investigation and demanding extra detailed details about Microsoft’s China-based assist operations.

    In response to the mounting strain, Microsoft introduced it had halted its use of China-based engineers to assist Protection Division cloud computing techniques and was contemplating implementing the identical change for different authorities cloud clients.

    The timing of those revelations is especially regarding given the scope of the current SharePoint assault. Microsoft’s evaluation confirmed that Chinese language hackers started exploiting SharePoint weaknesses as early as July 7, 2025.

    The corporate launched an preliminary patch on July 8, however hackers efficiently bypassed it, forcing Microsoft to situation a extra sturdy patch with enhanced protections.

    The U.S. Cybersecurity and Infrastructure Safety Company warned that these vulnerabilities allow hackers to “absolutely entry SharePoint content material, together with file techniques and inside configurations, and execute code over the community.”

    The assaults have additionally been used to unfold ransomware, which encrypts victims’ information and calls for fee for his or her launch.

    Affect and Future Implications

    Authorities businesses have reported various ranges of impression from the breach. The Division of Homeland Safety acknowledged there isn’t a proof that information was taken from the company, whereas the Division of Vitality, which oversees the Nationwide Nuclear Safety Administration, described the impression as “minimal” with no delicate or labeled info compromised.

    Wanting forward, Microsoft has introduced that starting subsequent July, it should not assist on-premises variations of SharePoint, urging clients emigrate to the web model.

    This transition aligns with Microsoft’s broader enterprise technique of selling subscription-based providers and its Azure cloud computing platform, which has considerably contributed to the corporate’s current valuation milestone of turning into the second firm in historical past to exceed $4 trillion in market worth.

    This investigation raises elementary questions concerning the safety protocols surrounding vital software program infrastructure and the potential dangers of worldwide staffing preparations in an more and more complicated cybersecurity panorama.

    Discover this Story Fascinating! Observe us on LinkedIn and X to Get Extra Instantaneous Updates.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    North Korean Hackers Use EtherHiding to Cover Malware Inside Blockchain Good Contracts

    October 16, 2025

    North Korean Hackers Deploy BeaverTail–OtterCookie Combo for Keylogging Assaults

    October 16, 2025

    Coming AI rules have IT leaders anxious about hefty compliance fines

    October 16, 2025
    Top Posts

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025

    Meta resumes AI coaching utilizing EU person knowledge

    April 18, 2025
    Don't Miss

    Google’s Veo 3.1 Simply Made AI Filmmaking Sound—and Look—Uncomfortably Actual

    By Amelia Harper JonesOctober 17, 2025

    Google’s newest AI improve, Veo 3.1, is blurring the road between artistic device and film…

    North Korean Hackers Use EtherHiding to Cover Malware Inside Blockchain Good Contracts

    October 16, 2025

    Why the F5 Hack Created an ‘Imminent Menace’ for 1000’s of Networks

    October 16, 2025

    3 Should Hear Podcast Episodes To Assist You Empower Your Management Processes

    October 16, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.