Microsoft Corp. is probing whether a leak from its early alert system for cybersecurity firms enabled Chinese hackers to exploit vulnerabilities in its SharePoint software before patches were released, according to people familiar with the matter who spoke to Bloomberg.
The technology giant’s investigation centers on the Microsoft Active Protections Program (MAPP), designed to provide vetted cybersecurity partners early information about newly discovered vulnerabilities, giving them a head start to prepare defenses before public disclosure. However, sources told Bloomberg that this program may have inadvertently facilitated the rapid and global exploitation of SharePoint flaws over recent days.
“As part of our standard process, we’ll review this incident, find areas to improve, and apply those improvements broadly,” a Microsoft spokesperson said in a statement, emphasizing the importance of partner programs in the company’s security response.
The Chinese Embassy in Washington dismissed the hacking allegations, citing statements from foreign ministry spokesman Guo Jiakun who said, “Cybersecurity is a common challenge faced by all countries and should be addressed jointly through dialogue and cooperation.” Guo reiterated China’s opposition to hacking and condemned what he called unfounded “smears and attacks” under the guise of cybersecurity concerns.
Microsoft has attributed the SharePoint breaches to state-sponsored Chinese groups, including Linen Typhoon, Violet Typhoon, and Storm-2603. Victims number over 400 organizations worldwide, including the U.S. National Nuclear Security Administration, responsible for the country’s nuclear weapons.
MAPP, now 17 years old, grants cybersecurity vendors—after strict vetting and nondisclosure agreements—access to patch details 24 hours before public release. A smaller group of highly trusted members receives notifications five days in advance. Dustin Childs, head of threat awareness at Trend Micro and a MAPP member, confirmed that the SharePoint vulnerabilities were included in recent MAPP alerts and acknowledged that “the possibility of a leak has certainly crossed our minds,” calling such a breach a “dire threat” to the program’s integrity.
The vulnerabilities were first publicly demonstrated in May by Vietnamese researcher Dinh Ho Anh Khoa at the Pwn2Own security conference, leading Microsoft to begin patch development. Yet hackers launched attacks on SharePoint servers the day before the patch’s public release on July 7, suggesting the flaws were exploited as soon as they became known to insiders.
While it’s possible attackers independently discovered the bugs, experts describe this as unlikely. Jim Walter, senior threat researcher at SentinelOne, noted that leaks from early warning programs have occurred before, referencing a 2012 incident when Microsoft removed a Chinese security company from MAPP for disclosing vulnerability information prematurely.
Microsoft also faced a major leak in 2021 involving Chinese MAPP partners and vulnerabilities in its Exchange servers, which led to a massive global hack attributed to the Chinese espionage group Hafnium. Bloomberg previously reported that Microsoft considered revising MAPP after that breach, though no public details on changes have since emerged.
Chinese cybersecurity companies involved in MAPP are sometimes also part of China’s government-run vulnerability database, overseen by the Ministry of State Security. According to experts like Eugenio Benincasa of ETH Zurich’s Center for Security Studies, this dual role raises concerns about transparency and potential conflicts between corporate commitments to Microsoft and obligations to Chinese state agencies.

