A foreign attacker, who has not yet been clearly identified, has gained access to the IT systems of an important US nuclear weapons factory. Access was achieved via vulnerabilities in Microsoft’s SharePoint server.
According to a report by the CSO magazine The hack affected the Kansas City National Security Campus (KCNSC) of the National Nuclear Security Administration (NNSA). According to information from security circles, the perpetrators used unpatched vulnerabilities in Microsoft’s SharePoint platform to break into the plant’s IT systems. The affected site in Kansas City, operated by Honeywell Federal Manufacturing & Technologies on behalf of the Department of Energy, is central to the production of non-nuclear components of American nuclear weapons. Around 80 percent of these components come from the factory in Missouri. Because of its importance, the facility is considered one of the most sensitive facilities in the US military.
According to an expert involved in the investigation, authorities discovered the attack in August, a few weeks after Microsoft released security updates for two vulnerabilities on July 19. These were a spoofing vulnerability (CVE-2025-53770) and a remote code execution vulnerability (CVE-2025-49704), which allowed attackers to execute malicious code on local servers. As early as July 22, the Energy Ministry confirmed that it had been affected by the attacks – but according to its own statement, only to a “minimal extent.”
It is still unclear who is behind the attack. Microsoft traces the wave of SharePoint exploits to three China-affiliated groups codenamed Linen Typhoon, Violet Typhoon and Storm-2603. They are said to have originally prepared the use of Warlock ransomware. A source familiar with the incident, however, believes Russian cyber criminals are responsible. The security company Resecurity also reports evidence of Chinese authors, but does not rule out Russian involvement.
It is possible that Russian actors independently reproduced the attack method after technical details were published in June. Meanwhile, experts warn of possible sideways movements by attackers from IT into the operational networks (OT), which are responsible for manufacturing and control processes. Although the production systems in Kansas City are considered largely isolated, there is no absolute security. “We need to carefully analyze how states could exploit IT vulnerabilities to gain access to industrial control systems,” said Jen Sovada of cybersecurity firm Claroty.
A fence proposal becomes useful only when it explains what will be built, who owns…
Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…
It's an open secret that Microsoft was working on a Windows Phone smartphone long before…
As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…
Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…
Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…