Microsoft Corp. has curtailed Chinese companies’ access to early notifications about cybersecurity vulnerabilities in its software, amid concerns that leaks may have contributed to recent hacking campaigns targeting its SharePoint and Exchange products.
The change, which took effect last month, affects participants in Microsoft’s Active Protections Program (MAPP), which provides security software companies around the world with early details of vulnerabilities so they can update protections for their customers faster. Microsoft will now provide affected Chinese firms with only general written descriptions of flaws instead of the detailed “proof of concept” code previously shared.
David Cuddy, a Microsoft spokesperson, said the adjustments target “countries where they’re required to report vulnerabilities to their governments,” a reference to China’s 2021 law mandating that companies or security researchers report any discovered cybersecurity flaw within 48 hours to China’s Ministry of Industry and Information Technology.
The move follows a series of cyberattacks Microsoft attributes to state-sponsored Chinese hackers, which exploited SharePoint vulnerabilities and affected more than 400 organizations, including the U.S. National Nuclear Security Administration. Microsoft had previously investigated whether details about the flaws had leaked from its MAPP partners, Bloomberg reported.
Concerns over leaks are not new. Microsoft alleged in 2012 that Hangzhou DPtech Technologies Co., a Chinese network security company, had violated a non-disclosure agreement, exposing a major Windows vulnerability. In 2021, Microsoft suspected at least two Chinese MAPP partners of leaking information about Exchange server vulnerabilities, triggering a global hacking campaign attributed to the Chinese espionage group Hafnium.
Dakota Cary, a China-focused consultant at U.S. cybersecurity firm SentinelOne, supported Microsoft’s decision. “It is very clear the Chinese companies in MAPP have to respond to incentives from the government,” Cary said. “So it makes sense to limit the information provided.”
In a related move, Microsoft confirmed for the first time that it has shut down “transparency centers” in China, where authorities could review Microsoft’s source code to ensure it contained no hidden backdoors. Cuddy said such facilities had “long been retired” and that “no one has visited one in China since 2019.” Microsoft had first provided this access in 2003 to give Chinese authorities confidence in the security of its Windows platform.
Cuddy emphasized that Microsoft continuously reviews MAPP participants and can suspend or remove companies that violate program rules, including prohibitions against participating in offensive attacks.
The decision marks a significant tightening of Microsoft’s cybersecurity information-sharing with Chinese firms and highlights the ongoing tension between global software companies and state-directed cyber activities.

