Monday 29 June, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

China alleges the US exploited Microsoft Exchange zero-day to target defence sector

Beijing accuses US intelligence of carrying out a year-long espionage campaign to steal sensitive military designs — a rare reversal in the nations’ long-running cyber blame game

Resilience MediabyResilience Media
August 11, 2025
in News
Photo by Yiran Ding on Unsplash

Photo by Yiran Ding on Unsplash

Share on Linkedin

China has formally accused US intelligence agencies of exploiting a previously unknown Microsoft Exchange zero‑day vulnerability to orchestrate a prolonged cyberattack against its defence sector.

You Might Also Like

Exclusive: Osney Capital closes £60M cyber fund to back UK’s next generation of security startups

Nokia resurfaces to help build Finland’s border guard anti-drone capability

Sanctioned Chinese cyber giant claims AI can rival Anthropic’s Mythos

China’s National Internet Emergency Response Center (CNCERT), which describes itself as a non-governmental cybersecurity technical center, alleges that US intelligence hackers leveraged the flaw in Microsoft’s Exchange software to breach and maintain control of the email server of a major Chinese military-related enterprise (which it did not name) between July 2022 and July 2023.

During this alleged cyber‑espionage campaign, CNCERT claims the perpetrators stole sensitive defence data and maintained persistent access throughout that period.

“The attacker … launched more than 40 network attacks, stealing the emails of 11 people, including the senior management of the enterprise, involving the relevant design schemes, system core parameters and other contents of our military industry products,” reads a version of CNCERT’s statement translated by Resilience Media.

CNCERT claimed that, in a separate instance, US agents exploited vulnerabilities in an electronic file system, unrelated to Microsoft Exchange, to conduct cyberattacks against another Chinese military enterprise operating in the communications and satellite internet sector between July and November 2024, also exfiltrating confidential information.

“The attacker used the enterprise’s system software upgrade service to deliver theft Trojan horses to the enterprise’s intranet, invaded and controlled more than 300 devices, and searched for keywords such as ‘military special network’ and ‘core network’ to steal sensitive data on the accused host,” reads CNCERT’s alert.

Guo Jiakun, spokesperson of the Ministry of Foreign Affairs of China, said in a statement that the “US used its allies in Europe and in China’s neighboring region … to launch the cyberattacks.” He added that CNCERT’s alleged findings are “the latest evidence of the US government’s malicious cyberattacks on China” and “once again shows that the US is the top cyber threat faced by China.”

In a 1 August alert, CNCERT added that these alleged attacks, which it claims have been aggressively carried out since the US National Security Agency (NSA)’s alleged cyberattack on China’s Northwestern Polytechnical University in 2022, pose “a serious threat to the scientific research and production security of China’s defense and defense industries, and even to national security.”

Neither Microsoft nor the NSA immediately responded to Resilience Media’s questions.

These accusations follow a broader pattern of mutual cyberespionage allegations between Beijing and Washington. China’s latest claims echo earlier US assertions that Chinese state‑sponsored hackers have targeted its systems.

Notably, in 2021, Microsoft revealed that China-linked threat group Hafnium, also known as Silk Typhoon, had exploited multiple zero‑day vulnerabilities in Exchange to launch widespread intrusions across the globe. Those attacks affected tens of thousands of servers, including those belonging to US defense contractors, law firms, universities, NGOs, and healthcare research institutions. In response, Microsoft and international authorities issued patches and warnings to mitigate the damage.

Just last month, Microsoft said China-backed hacking groups had also exploited flaws in SharePoint to target governments and businesses that use the file-sharing software.

The UK’s National Cyber Security Centre told the BBC that these attacks, which focused on stealing intellectual property from organisations related to defense and strategic planning, targeted “a limited number” of SharePoint Server customers in the UK.

CNCERT’s latest allegations represent a rare reversal of narrative: China is now asserting that the US deployed analogous tactics against Chinese military‑industrial targets, underscoring intensifying tensions in cyberspace between the world’s two largest economies.

China’s accusations come just weeks after Ukraine’s national cyber authority warned that Russian state-backed hackers had been using AI-powered malware in active attacks targeting the country’s defence and security sector.

Tags: ChinaCNCERTGuo JiakunMicrosoft
Previous Post

BAE backs Oxford Dynamics to bolster UK defence autonomy with AI

Next Post

BAE Invests in a Startup; US Accused of Chinese Cyberattack; Darkstar Bootcamp returns to Kyiv (quiet week)

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

Exclusive: Osney Capital closes £60M cyber fund to back UK’s next generation of security startups

byCarly Page
June 29, 2026

Osney Capital has closed its debut cybersecurity fund at a £60 million hard cap after investors piled in beyond its...

Nokia resurfaces to help build Finland’s border guard anti-drone capability

Nokia resurfaces to help build Finland’s border guard anti-drone capability

byJohn Biggs
June 26, 2026

Nokia announced its participation in an industrial consortium led by the Finnish Border Guard to build anti-drone systems for government...

a chinese flag hanging from the side of a building

Sanctioned Chinese cyber giant claims AI can rival Anthropic’s Mythos

byCarly Page
June 26, 2026

A Chinese cybersecurity company sanctioned by the US claims it has developed an artificial intelligence system capable of hunting software...

SE3 Labs unveils its spatial AI tools for defence backed by Lakestar and Sequoia Scouts

SE3 Labs unveils its spatial AI tools for defence backed by Lakestar and Sequoia Scouts

byIngrid Lunden
June 26, 2026

Large Language Models are changing how non-technical people engage with AI, and those learnings are permeating into the world of...

Copenhagen-based startup Acodyne lands €2.5 million pre-seed round for autonomous cargo drones

Copenhagen-based startup Acodyne lands €2.5 million pre-seed round for autonomous cargo drones

byJohn Biggs
June 25, 2026

Copenhagen-based Acodyne announced it has raised €2.5 million in pre-seed funding to help build autonomous cargo aircraft designed for "heavy...

Nearfield Instruments

Nearfield Instruments raises $380M to stake Europe’s claim in the global chip supply chain

byPaul Sawers
June 25, 2026

Sovereignty has emerged as one of the defining strategic preoccupations in Europe today, intersecting with almost every aspect of national...

Irish space tech firm Ubotica raises $11M

Irish space tech firm Ubotica raises $11M

byFiona Alston
June 24, 2026

Ubotica, the Irish space tech firm developing orbital AI for satellites, has raised $11 million to scale the commercialisation of...

Dutch semiconductor company is bringing secure, authenticated satellite positioning to handheld devices

Dutch semiconductor company is bringing secure, authenticated satellite positioning to handheld devices

byJohn Biggs
June 23, 2026

For years, authenticated satellite positioning has largely been reserved for expensive, power-hungry systems operating in defence, aviation, and other specialised...

Load More
Next Post
BAE Invests in a Startup; US Accused of Chinese Cyberattack; Darkstar Bootcamp returns to Kyiv (quiet week)

BAE Invests in a Startup; US Accused of Chinese Cyberattack; Darkstar Bootcamp returns to Kyiv (quiet week)

Milrem and Frontline partner to power up Milrem’s THeMIS vehicles with BURIA grenade systems

Milrem and Frontline partner to power up Milrem’s THeMIS vehicles with BURIA grenade systems

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Senai exits stealth to help governments harness online video intelligence

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.