Microsoft Curbs Vulnerability Info Access for Chinese Firms

2025-08-23
Microsoft Curbs Vulnerability Info Access for Chinese Firms

Following July's SharePoint zero-day attacks, seemingly linked to a leak in Microsoft's early-bug-notification program (MAPP), Microsoft has reportedly stopped providing Chinese companies with proof-of-concept exploit code for upcoming vulnerabilities. MAPP typically gives vendors two weeks' advance notice before Patch Tuesday, but now access is restricted for companies in countries required to report vulnerabilities to their governments, including China. These companies will receive general written descriptions instead of PoC code. Security experts see this as a positive step to prevent future leaks.

Tech