| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|
| Su | Mo | Tu | We | Th | Fr | Sa |
|---|---|---|---|---|---|---|

A program to share information with cybersecurity companies may have exposed unpatched flaws in the company's SharePoint service.

Both Microsoft and Trend Micro later said that hackers had actually begun exploiting the bugs on July 7, a day before the patches. It is unclear how these hackers learned of these flaws, Childs said. Trend Micro said a technology company—which it declined to identify—was compromised in the attack that it observed.

The vulnerability opening the way for the attack was first identified in May at a Berlin hacking competition organised by cybersecurity firm Trend Micro that offered cash bounties for finding computer bugs in popular software.

Both techniques remain popular with state-sponsored and cybercriminal groups, says Peter Girnus, a senior threat researcher with cybersecurity firm Trend Micro's Zero Day Initiative (ZDI).

Louise McEvoy, Trend Micro’s vice president of U.S. channel, told CRN in an email that the vendor is “working to ensure that the changes within Microsoft’s MVI program strengthen our joint business.”