Technology

Foreign attacker breaches US nuclear weapons factory via unpatched SharePoint flaws

A foreign attacker, who has not yet been clearly identified, has gained access to the IT systems of an important US nuclear weapons factory. Access was achieved via vulnerabilities in Microsoft’s SharePoint server.

Newly discovered gaps

According to a report by the CSO magazine The hack affected the Kansas City National Security Campus (KCNSC) of the National Nuclear Security Administration (NNSA). According to information from security circles, the perpetrators used unpatched vulnerabilities in Microsoft’s SharePoint platform to break into the plant’s IT systems. The affected site in Kansas City, operated by Honeywell Federal Manufacturing & Technologies on behalf of the Department of Energy, is central to the production of non-nuclear components of American nuclear weapons. Around 80 percent of these components come from the factory in Missouri. Because of its importance, the facility is considered one of the most sensitive facilities in the US military.

According to an expert involved in the investigation, authorities discovered the attack in August, a few weeks after Microsoft released security updates for two vulnerabilities on July 19. These were a spoofing vulnerability (CVE-2025-53770) and a remote code execution vulnerability (CVE-2025-49704), which allowed attackers to execute malicious code on local servers. As early as July 22, the Energy Ministry confirmed that it had been affected by the attacks – but according to its own statement, only to a “minimal extent.”

Speculation about the perpetrators

It is still unclear who is behind the attack. Microsoft traces the wave of SharePoint exploits to three China-affiliated groups codenamed Linen Typhoon, Violet Typhoon and Storm-2603. They are said to have originally prepared the use of Warlock ransomware. A source familiar with the incident, however, believes Russian cyber criminals are responsible. The security company Resecurity also reports evidence of Chinese authors, but does not rule out Russian involvement.

It is possible that Russian actors independently reproduced the attack method after technical details were published in June. Meanwhile, experts warn of possible sideways movements by attackers from IT into the operational networks (OT), which are responsible for manufacturing and control processes. Although the production systems in Kansas City are considered largely isolated, there is no absolute security. “We need to carefully analyze how states could exploit IT vulnerabilities to gain access to industrial control systems,” said Jen Sovada of cybersecurity firm Claroty.

Recent Posts

GameStop boss: Game disks are completely irrelevant

GameStop does not see itself under pressure from the foreseeable end of physical PlayStation games.…

10 hours ago

Linux kernel update leads to performance decline on AMD GPUs

An upcoming Ubuntu kernel update brutally slows down AMD GPUs: The update to version 7.0.0-28.28…

10 hours ago

Tasteless but expensive: luxury gold cell phones honor Messi and Ronaldo

The luxury brand Caviar is celebrating the 2026 World Cup with exclusive special editions. The…

10 hours ago

Switch 1 & 2: Nintendo may be working on a smart universal dock

A patent that has surfaced suggests that Nintendo could be working on a universal dock…

10 hours ago

Steam Sales: Valve reveals dates for all discount promotions until July 2027

The dates for all upcoming sales on Valve's gaming platform Steam in the first half…

10 hours ago

Spotify: Former premium function is now free for all users

Spotify is unlocking a previous premium feature for all users. From now on, managed user…

10 hours ago