Microsoft identified three China-linked cyber groups, Linen Typhoon, Violet Typhoon, and Storm-2603, exploiting SharePoint vulnerabilities to gain unauthorized access and steal sensitive data. The attacks involved sending POST requests to the ToolPane endpoint, bypassing authentication, and using malicious scripts to extract cryptographic keys. Microsoft urges immediate patching and additional security measures to mitigate risks.