Short answer: ProPublica documented that Microsoft used a China-based engineering team to maintain SharePoint, including the on-premises product later targeted in 2025. China-linked threat groups did exploit SharePoint Server vulnerabilities, but no public evidence establishes that those engineers caused, enabled, or participated in the intrusion.
What ProPublica reported
In an August 1, 2025 investigation, ProPublica said it reviewed screenshots of Microsoft’s internal work-tracking system showing China-based employees fixing bugs for “SharePoint OnPrem.” That is the self-hosted SharePoint Server product, not the Microsoft 365-hosted service. ProPublica reported that the arrangement had existed for years. ProPublica’s report is the basis for the staffing claim.
Microsoft confirmed that a China-based team existed. Microsoft said the team was supervised by a U.S.-based engineer, followed Microsoft security requirements, and had its code reviewed by managers. It also said work was being moved to another location. Those are Microsoft’s stated controls, not independent findings.
The public record does not identify each engineer’s permissions, repositories, build systems, production access, or access to customer environments. Maintaining product code is not the same as logging in to a customer’s live farm or viewing customer data.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
What the 2025 attack actually involved
Microsoft said attackers were actively exploiting vulnerabilities in on-premises SharePoint Server. SharePoint Online in Microsoft 365 was not affected by the vulnerabilities covered in its July 2025 guidance. Microsoft’s customer guidance identified supported affected products as SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Microsoft’s threat-intelligence account described an earlier spoofing flaw, CVE-2025-49706, and remote-code-execution flaw, CVE-2025-49704. Attackers then exploited CVE-2025-53770 and CVE-2025-53771 after earlier July fixes did not fully protect every customer. Microsoft’s July 22 account describes that sequence.
CISA said the vulnerabilities could let attackers reach SharePoint content, file systems, and internal configuration and execute code over the network. Its alert and malware analysis provide technical indicators and affected CVEs: CISA alert and CISA malware analysis.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Who was reported as exploiting it?
TechRepublic’s summary of the reporting associated exploitation with the China-linked groups Linen Typhoon, Violet Typhoon, and Storm-2603; it reported that Storm-2603 deployed Warlock ransomware. These are threat-actor assessments, not proof that the Chinese government ordered every intrusion. TechRepublic’s account distinguishes those assessments from the separate question of an insider compromise.
Free tools Windows power users keep installed
One-click scans. No signup required.
Does the evidence show Microsoft’s China-based engineers caused the breach?
No. The evidence shows a potentially consequential overlap:
- China-based staff reportedly maintained the affected product.
- Internal records reportedly showed recent SharePoint bug-fixing activity.
- China-linked groups exploited SharePoint vulnerabilities.
- Microsoft acknowledged the team and said it was relocating the work.
It does not show that a particular engineer introduced a flaw, disclosed a vulnerability, accessed a customer farm, or cooperated with attackers. ProPublica reported that any role by the China-based staff in the hack remained unclear. “China-based” also does not, by itself, establish Chinese-government control or coercion.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
The questions Microsoft’s safeguards leave open
- Did U.S. supervision include independent technical review and reproducible builds?
- Were source repositories segmented and privileged credentials restricted?
- Were all code, test, and administrative accesses logged and audited?
- Were engineers barred from production systems and customer support environments?
- Did the arrangement cover only engineering, or also operational support?
Those are legitimate supply-chain and governance questions. They are not evidence that the SharePoint attack was an insider operation.
Timeline of the overlap
| Date | Event |
|---|---|
| May 2025 | TechRepublic reported that ToolShell-related exploit activity was identified at a hacking competition. |
| July 7, 2025 | Microsoft said its analysis showed Chinese hackers exploiting SharePoint weaknesses by this date. |
| July 8, 2025 | Microsoft released an initial patch that attackers reportedly bypassed. |
| July 19, 2025 | Microsoft published emergency customer guidance describing active attacks. |
| July 22, 2025 | Microsoft published its threat-intelligence account. |
| August 1, 2025 | ProPublica published its report on China-based SharePoint maintenance. |
| July 14, 2026 | SharePoint Server 2016 and 2019 reached Microsoft end of support. |
| August 18, 2026 | Those two versions remain beyond support; Subscription Edition remains supported under its lifecycle policy. |
Why the “digital escort” controversy is related but different
ProPublica separately reported that Microsoft used foreign-based personnel, including China-based workers, to maintain cloud systems supporting U.S. government agencies. U.S.-based “digital escorts” were meant to supervise or control access; ProPublica reported concerns that some escorts lacked the technical expertise to monitor foreign engineers effectively. See the Pentagon report and the government-support report.
That reporting concerns support for government cloud systems, while the SharePoint allegation concerns product engineering. The stories raise a common governance issue, but they do not demonstrate that the same people, credentials, or access path caused the SharePoint attacks.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
ProPublica later reported that Microsoft said it had stopped using China-based engineers for Defense Department cloud support and was considering similar changes for other government customers. The Defense Department tightened requirements for personnel from adversarial countries, technical qualifications, and audit trails. Those rules apply to Defense Department systems and procurement; they do not automatically govern commercial SharePoint customers. Pentagon restrictions and related reporting provide that context.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Which SharePoint versions need attention now?
| Product | Status as of Aug. 18, 2026 | Implication |
|---|---|---|
| SharePoint Server 2016 | Support ended July 14, 2026 | No longer a supported long-term platform; see Microsoft’s lifecycle page. |
| SharePoint Server 2019 | Support ended July 14, 2026 | Plan migration or upgrade; see Microsoft’s lifecycle page. |
| SharePoint Server Subscription Edition | Supported under the Modern Lifecycle Policy, subject to supported builds | Requires recurring public updates; see lifecycle details and the servicing FAQ. |
| SharePoint Online | Not affected by the cited 2025 SharePoint Server vulnerabilities | Cloud identity, configuration, insider-risk, and account-compromise controls still matter. |
What administrators should do
- Identify the deployment. Confirm whether each workload is SharePoint Online or an on-premises farm, then record the farm version, build, servers, language packs, and internet exposure.
- Patch every server. Microsoft’s July guidance listed KB5002768 for Subscription Edition; KB5002754 plus language-pack KB5002753 for SharePoint Server 2019; and KB5002760 plus language-pack KB5002759 for SharePoint Server 2016. Verify current Microsoft guidance and update history rather than relying on this static list.
- Complete the farm upgrade. Installing binary files may not finish the SharePoint upgrade process. Follow Microsoft’s software-update procedure and apply required language-dependent updates: software updates overview.
- Enable defenses. Configure Antimalware Scan Interface, use AMSI Full Mode where available, and deploy Microsoft Defender Antivirus or an equivalent solution.
- Rotate machine keys. Microsoft advised rotating SharePoint ASP.NET machine keys. Treat this as coordinated key and credential remediation, especially after suspected exploitation.
- Reduce exposure during remediation. If AMSI cannot be enabled, disconnect the server from the internet where feasible or restrict access through a VPN, authenticated proxy, or authentication gateway.
- Investigate before rebuilding. Preserve evidence; review IIS, SharePoint, Windows, PowerShell, identity-provider, endpoint, and network logs; search for web shells and unexpected files; check new or modified service accounts, privileged identities, persistence, and lateral movement into SQL Server, Active Directory, file shares, Exchange, Teams, OneDrive, and management systems.
- Choose a supported destination. Evaluate Subscription Edition for continued self-hosting or SharePoint Online for Microsoft-managed operations. Base the choice on sovereignty, accreditation, custom integrations, staffing, identity maturity, and data-governance requirements.
Migration and operating trade-offs
Remain on premises temporarily
This may be necessary for sovereignty, regulatory, contractual, network-isolation, or specialized-accreditation requirements. It leaves the organization responsible for patching, segmentation, privileged access, monitoring, and incident response.
Move to Subscription Edition
Subscription Edition preserves an on-premises deployment with a continuing-update model. It still requires licensing, infrastructure, compatibility testing, and disciplined recurring updates; it does not remove the security burden of self-hosting.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteMigrate to SharePoint Online
SharePoint Online can reduce server-patching work and integrate with Microsoft 365. It does not eliminate identity attacks, misconfiguration, insider risk, or data-governance obligations. Migration should inventory custom solutions, workflows, permissions, metadata, retention, search, and residency requirements before cutover.
Bottom line
ProPublica’s reporting establishes a China-based SharePoint maintenance arrangement and Microsoft’s decision to move that work. Microsoft and CISA establish that China-linked actors exploited serious on-premises SharePoint vulnerabilities. The public evidence does not connect the engineers to the intrusion. For organizations, the actionable conclusion is narrower and more urgent: identify any on-premises farm, patch and investigate it as a potential compromise, rotate keys where appropriate, and retire unsupported SharePoint 2016 or 2019 through a supported upgrade or migration.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




