Category: DJF

  • MIL-OSI Russia: China’s Vice Chairman Meets Pakistani Military Leader

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    BEIJING, July 25 (Xinhua) — Chinese Vice President Han Zheng met with Pakistan Chief of Army Staff Asim Munir in Beijing on Friday.

    China and Pakistan have a strong and unbreakable friendship and are all-weather strategic cooperation partners, Han Zheng said during the meeting. According to him, a high degree of mutual trust, solidarity in the face of challenges and a common destiny are the distinctive features of China-Pakistan relations.

    China stands ready to work with Pakistan to implement the important consensus reached by the two leaders, deepen all-weather friendship, expand all-round cooperation, and accelerate the building of a closer China-Pakistan community with a shared future in the new era.

    The general consensus of Pakistani society is to develop friendly cooperation with China, A. Munir pointed out in turn. He stated that Pakistan supports China’s three global initiatives and firmly stands by China’s side.

    The Pakistan Army is ready to further implement the consensus reached by the leaders of the two countries and continuously deepen the all-weather strategic cooperation and partnership between Pakistan and China, a Pakistani military chief said. -0-

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • At least 5 students killed as school roof collapses in Rajasthan’s Jhalawar; PM Modi, President Murmu express grief

    Source: Government of India

    Source: Government of India (4)

    At least five students were killed and several injured after the roof of a primary school collapsed in Rajasthan’s Jhalawar district on Friday.

    The incident occurred in Piplodi village, located in the Manoharthana area, shortly after the morning prayers.

    According to Rajasthan Education Minister Madan Dilawar, around 25 to 30 students were in the classroom when the roof suddenly caved in.

    The victims were students of Class 7, all of whom were trapped under the debris. Locals and school staff rushed to the scene to rescue the injured, who were immediately taken to the nearby Manoharthana Hospital.

    Dr. Kaushal Lodha from the hospital told IANS that 11 students, critically injured in the collapse, were referred to the district hospital in Jhalawar for advanced medical care.

    Rescue operations were ongoing at the site, with emergency personnel working to ensure that no one remained trapped.

    Prime Minister Narendra Modi, who is currently on a two-day visit to the Maldives, expressed deep sorrow over the incident.

    In a post on X, the Prime Minister’s Office wrote: “The mishap at a school in Jhalawar, Rajasthan, is tragic and deeply saddening. My thoughts are with the affected students and their families in this difficult hour. Praying for the speedy recovery of the injured. Authorities are providing all possible assistance to those affected.”

    President Droupadi Murmu also conveyed her condolences, calling the incident “extremely tragic.” In a message posted on X, she said: “I pray that God grants strength to the grieving families to bear this pain. I wish for the speedy recovery of the students injured in this accident.”

    Rajasthan Chief Minister Bhajan Lal Sharma described the tragedy as “painful and heart-wrenching,” and said officials had been directed to ensure the injured children receive the best possible medical care.

    “May God grant a place at His divine feet to the departed noble souls and give strength to the grief-stricken families to bear this immense sorrow,” he said in his post.

    (With inputs from IANS)

  • MIL-OSI Russia: Call for Papers: International Conference on Topical Issues in Nuclear Installation Safety

    Translation. Region: Russian Federal

    Source: International Atomic Energy Agency –

    An important disclaimer is at the bottom of this article.

    TIC2026 will bring together nuclear safety regulators, plant designers and operators, technical support organisations and other stakeholders from various countries, as well as international organisations. The aim is to increase knowledge on key topics related to the safety of nuclear installation design, safety assessment, siting, construction, operation and regulation of both existing and new nuclear installations.

    According to the boss IAEA Safety Assessment Sections Ana Gomes, “The Conference will provide a comprehensive forum where nuclear safety stakeholders representing different generations of nuclear projects and a wide range of nuclear safety areas will be able to address a wide range of nuclear safety issues, making it a truly inclusive event.”

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Asia-Pac: Director General David Cheng-Wei Wu Attended the 114th Double Tenth Celebration Committee’s Second Meeting

    Source: Republic of China Taiwan

    The 114th Double Tenth Celebration Committee held its second meeting, where Chairperson Michael Wu briefed community leaders on the planning progress. He also unveiled this year’s theme and logo — “Legacy in Motion” — symbolizing the brilliance of Taiwan’s history and the wisdom passed down through generations. In an era of rapid innovation, it highlights how tradition and technology can converge in harmony, guiding Taiwan boldly into the future.
    Director General David Cheng-Wei Wu commended Michael and his team for their precise planning, as reflected in the meeting handbook—demonstrating the quality and efficiency of Taiwanese entrepreneurship. He looks forward to the community’s strong support and active participation in both the National Day Reception hosted by TECO Sydney, and the National Day Dinner organized by the Celebration Committee.

    MIL OSI Asia Pacific News

  • MIL-OSI Europe: Climate – Advisory opinion by the International Court of Justice (ICJ) on Obligations of States in respect of Climate Change (July 24, 2025) (24.07.25)

    Source: Republic of France in English
    The Republic of France has issued the following statement:

    On March 29, 2023, the UN General Assembly requested, via a resolution co-sponsored by all EU Member States, an advisory opinion from the International Court of Justice concerning the obligations of States in respect of climate change. Questions submitted to the Court for their opinion dealt with States’ international obligations with respect to the protection of the climate system and the environment from anthropogenic greenhouse gas emissions and the ensuing legal consequences for States.

    Along with some 100 States and international organizations, France took part in this advisory process by filing written statements with the Court and participating in arguments. France defended an ambitious reading of the Paris Climate Agreement and called on all States to abide by their obligations to protect the climate system and other environmental components.

    France takes note of the opinion issued by the Court on July 23, which marks an end to these historic proceedings. This landmark opinion will be studied very closely.

    France reaffirms its unwavering commitment to the ICJ. It will continue working ambitiously to achieve its climate goals and to support its partners.

    MIL OSI Europe News

  • MIL-OSI Africa: Her Excellency (H.E.) Bridget Motsepe-Radebe to Headline WomenIN Festival 2025 as Keynote Speaker

    Source: APO

    The WomenIN (WiN) (www.WeAreWomenIN.com) Festival is proud to announce Her Excellency Bridget Motsepe-Radebe, Chairman & Founder of Mmakau Mining and Ambassador for Economic Development at the Pan-African Parliament, as the official keynote speaker for the highly anticipated WomenIN Festival 2025, taking place from 13–14 November 2025 in Cape Town, South Africa.

    Renowned for her bold leadership, advocacy for gender and economic equality, and trailblazing legacy in the mining sector, H.E. Motsepe-Radebe has consistently broken barriers and redefined power and influence on the continent. Her presence at this year’s festival is set to ignite conversations, inspire generations, and elevate the mission of WomenIN — to connect, empower, and celebrate women across industries and borders.

    “Having H.E. Bridget Motsepe-Radebe headline this year’s WomenIN Festival is a full-circle moment for so many of us,” says Naz Fredericks Maharaj, Director of the WomenIN Portfolio. “She is a living symbol of what it means to lead with both courage and conviction. Her voice reflects the essence of this year’s theme — Limitless. No Labels. No Limits. No Apologies. We are honoured to welcome her to the stage, and even more excited for what her message will unlock in every woman attending this year’s festival.”

    The WomenIN Festival brings together women leaders, entrepreneurs, creatives, and changemakers from diverse sectors including mining, energy, mobility, finance, fashion, media, and the green economy. With a curated program of thought-provoking dialogues, fireside chats, capacity-building sessions, live activations, and power networking, the festival is a movement — not just a moment.

    This keynote announcement marks the first of many exciting speaker and program reveals as the WomenIN team rolls out its boldest edition yet.

    Tickets are officially on sale — reserve your seat and be part of a movement that’s shaking the world:

    Visit www.WeAreWomenIN.com to get your ticket, sponsor someone else’s, or explore partnership opportunities.

    Come as you are. Leave ignited.

    Distributed by APO Group on behalf of VUKA Group.

    Additional Links:
    Website: www.WeAreWomenIN.com
    Link to tickets : https://apo-opa.co/450gy1h

    WomenIN (WiN): Empowering Women, Breaking Barriers, Creating Impact
    WomenIN is a powerful cross-sector movement that connects, inspires, and uplifts women across Africa through collaboration, leadership, and sustainable development. From energy and mobility to retail, gaming, and the green economy, WiN is driving real change by building inclusive ecosystems where women can thrive.

    Through a range of in-person gatherings, digital content, workshops, and sector-specific initiatives, WomenIN provides a trusted platform for female professionals, entrepreneurs, changemakers, and allies to grow together, break silos, and co-create solutions for Africa’s future. With a strong focus on capacity building, leadership development, and market access for female-owned businesses, WomenIN is building a legacy of impact for generations to come.

    Whether you’re a corporate, NPO, SMME, or individual changemaker, there is space for you at the table—because we win when we WiN together.

    For more information, please visit: www.WeAreWomenIN.com or contact our team at info@wearewomenin.com.

    ABOUT VUKA Group:
    VUKA Group brings people and organisations together to connect with information and each other in meaningful conversations that drive growth and transformation across Africa’s industries. With 20+ years of experience on the continent, the group delivers sector-leading platforms across Energy, Mining, Smart Mobility, Transport, Retail, and Women Empowerment.

    The WomenIN (WiN) portfolio is a flagship initiative of VUKA Group, championing gender inclusivity and creating opportunities for women to lead, influence, and innovate across sectors. With a proudly African team and a commitment to sustainable development, VUKA is creating a future where everyone has the opportunity to rise.

    Learn more at: www.WeAreWomenIN.com

    Media files

    .

    MIL OSI Africa

  • MIL-OSI Africa: The Gambia: African Development Fund Approves $19.93 Million Grant to Tackle Fragility and Expand Opportunities for Rural Youth and Women

    Source: APO

    The Board of Directors of the African Development Bank Group (www.AfDB.org) has approved $19.93 million grant funding for the Resilience Building – Vulnerable Youth and Women Support Project, designed to improve access to basic social services for underserved communities in The Gambia.

    The initiative seeks to address the root causes of poverty and irregular migration by creating sustainable livelihoods and tackling early signs of fragility and preventing structural drivers of conflict and instability in the targeted region. It forms part of the Bank’s scaled-up prevention agenda under the Prevention Envelope of the Transition Support Facility (TSF), which emphasizes early response to fragility risks and systematic drivers of conflict.

    The Gambia faces severe economic challenges, with 53.4% of the population living below the poverty line. Poverty is particularly severe in rural areas, affecting 76 percent of residents, compared to 34 percent in urban areas. Youth unemployment stands at 38.6%, with women disproportionately impacted — 1.3 unemployed women for every unemployed man. These socio-economic disparities, coupled with limited access to services, are major push factors fuelling irregular migration and social instability.

    Although the country has achieved robust electricity access nationwide, glaring regional inequalities persist. In areas such as Kuntaur and Janjanbureh, fewer than one in four people have access to electricity, compared to 95 percent in the capital. Additionally, one in four children suffers from malnutrition. By targeting these gaps, the project aims to renew the social contract and foster community resilience.

    “This project represents our commitment to tackling the foundational causes of fragility, poverty, exclusion, and lack of opportunity, by investing in people and systems that build community resilience and hope,” said Dr. Joseph Ribeiro, African Development Bank Deputy Director General for West Africa, and Country Manager for The Gambia. “Through the TSF Prevention Envelope, we are acting early to prevent conflict and youth migration by fostering inclusive growth, gender equality, and institutional stability, while building foundations for sustainable livelihoods that will keep families and communities together.”

    The project will directly create 1,500 jobs, enhance productivity for 5,000 existing positions, and provide annual skills training to 500 youth in high-demand sectors such as agriculture, engineering, ICT, and renewable energy. In addition, support will be extended to 500 women-led micro and small enterprises and 50 women’s cooperatives.

    Key investments in health infrastructure will include rehabilitating four primary health facilities vulnerable regions, including Basse, Kuntaur, and Janjanbureh, where maternal mortality and child malnutrition rates exceed national averages. Enhanced nutrition surveillance systems will enable early detection for 22,000 children and facilitate treatment for 1,000 children requiring specialized care.

    Food insecurity has surged, rising from 13.4 percent in 2021 to 29 percent in 2023, with peaks of 61 percent in areas such as Kuntaur. The project will address this crisis by promoting climate-smart agriculture and strengthening local values chains to improve food security and reduce vulnerability to climate shocks.

    Financial inclusion is a core pillar of the intervention. With 77 percent of Gambian youth currently excluded from formal financial services, the project will establish dedicated credit lines and provide business development support to unlock entrepreneurship, particularly for women who face systemic barriers to accessing capital and markets.

    The initiative also includes scaling up efforts to tackle gender-based violence and inequality, and capacity-building for government institutions to enhance data-driven policymaking and long-term monitoring of fragility trends.

     Civil society organisations, including the Association of Non-Governmental Organizations (TANGO), will be central to ensuring the project is inclusive, participatory, and aligned with national priorities.

    Distributed by APO Group on behalf of African Development Bank Group (AfDB).

    Media Contact:
    Natalie Nkembuh,
    Communication and Media Relations Department
    media@afdb.org

    About the African Development Bank Group:
    The African Development Bank Group is Africa’s premier development finance institution. It comprises three distinct entities: the African Development Bank (AfDB), the African Development Fund (ADF) and the Nigeria Trust Fund (NTF). On the ground in 41 African countries with an external office in Japan, the Bank contributes to the economic development and the social progress of its 54 regional member states. For more information: www.AfDB.org

    Media files

    .

    MIL OSI Africa

  • Indian men’s hockey team to tour Australia for four-match series in August

    Source: Government of India

    Source: Government of India (4)

    The Indian men’s hockey team is set to tour Australia in August for a four-match series, scheduled to be held at the Perth Hockey Stadium from August 15 to 21.

    The matches will be played on August 15, 16, 19, and 21.

    The two sides recently faced each other in the FIH Pro League 2024–25 in Europe, where Australia edged out India 3–2 in both legs. However, India had earlier scripted a memorable 3–2 victory over the Kookaburras at the 2024 Paris Olympics — their first Olympic win over Australia since the 1972 Munich Games.

    While recent encounters have been closely fought, Australia have historically held the edge in the rivalry, winning 35 of the 51 matches played between the two teams since 2013. India have won nine times, with seven matches ending in draws.

    The series will serve as an important preparation phase for India ahead of the Asia Cup 2025, set to be held in Rajgir, Bihar, from August 29 to September 7. The tournament offers a direct qualification spot for the FIH Hockey Men’s World Cup 2026, making the Australia tour a key milestone in India’s buildup.

    Speaking about the tour, chief coach Craig Fulton said, “This tour comes at a crucial time for us, just ahead of the Asia Cup in Bihar. While these are technically friendly matches, they form a very important part of our preparation phase. Playing against a team like Australia will test us in all aspects — both on the ball and off it — and that is exactly what we need to sharpen up before a major tournament.”

    “We have just completed a 10-day training block, and the mood in the camp is upbeat as we are fully focused on what lies ahead. One of our key goals on this tour is to use the first two matches for selection purposes, while the remaining games will be played with the shortlisted squad for the Asia Cup. Our focus is firmly on moving forward — the goal now is to prepare well and go to the Asia Cup with the intent to win it,” he added.

    —IANS

  • MIL-OSI United Kingdom: Pillars of support for Derby’s biodiversity

    Source: City of Derby

    Biodiversity is set to flourish in Derby as 15 new Living Pillars are installed across the city centre, bringing natural beauty into urban spaces.

    Living pillars are self-contained vertical habitats attach to existing lamp posts and signage columns, supporting pollinators and improving the look and feel of the city.

    Powered by solar energy, each pillar is self-sufficient, collecting and recycling rainwater to keep its plants healthy year-round. In addition to their environmental benefits, the pillars will support wayfinding throughout the city, guiding residents and visitors to key destinations and attractions.

    Funded by Bauer Media Outdoor UK’s Community Innovation Fund and designed and installed by Scotscape, the Living Pillars are a step toward reintroducing nature to the heart of the city.

    Planted with resilient, long-lasting species such as Agastache ‘Summer Sunset’, Coreopsis ‘Rum Punch’, Heuchera ‘Coral Petite’ and Juniperus ‘Mint Julep’, the pillars are carefully designed to provide year-round colour and structure, while offering vital food and shelter for urban pollinators like bees, butterflies, and hoverflies.

    Building on the success of the recently installed planters and pocket parks around the city centre, the pillars are another step towards enhancing biodiversity and creating a greener, more vibrant city.

    Councillor Carmel Swan, Cabinet Member for Transport and Sustainability, said:

    Living pillars will be a brilliant addition to the work we’ve been doing over the past few months to bring more life into our city centre.  

    We’re serious about our commitment to creating a greener, healthier city that supports our residents, and the installation of these pillars is another step towards achieving this.

    Angus Cunningham, Scotscape Founder, said:

    Derby has shown bold leadership in embracing living infrastructure, which not only support biodiversity but also champion innovative, sustainable design in its urban spaces.

    Nigel Godfrey, Portfolio Partnership Manager, Central Region at Bauer Media Outdoor, added:

    It’s great to see ideas like this come to life in the heart of Derby. These Living Pillars are a small but mighty way to bring nature back into the city, and we’re proud to support them through our Community Innovation Fund. Alongside our Bee Bus Stops, they demonstrate how even everyday infrastructure can help boost biodiversity when creativity and sustainability work together to make public spaces greener and more enjoyable for everyone.

    Living Pillars are part of an ongoing partnership between the council and Bauer Media Outdoor, who operate the digital advertising screens housed under the innovative Bee Bus Stops located across Derby.

    The installation of living pillars reflects Derby’s wider environmental strategy and its commitment to creating greener, healthier places for people and nature to thrive.

    Work to install the pillars is currently underway and will be completed later this summer.

    MIL OSI United Kingdom

  • MIL-OSI Russia: Financial news: Information on funds attracted and placed by credit institutions

    Translation. Region: Russian Federal

    Source: Central Bank of Russia –

    An important disclaimer is at the bottom of this article.

    Information on funds attracted by credit institutions

    Volume of deposits from individuals attracted by credit institutions

    More Collapse –

    The volume of funds attracted by credit institutions from legal entities

    More Collapse –

    Volume of savings (deposit) certificates, bonds and bills issued by credit institutions

    More Collapse –

    Data on the amounts of bills of exchange discounted by credit institutions

    More Collapse –

    Data on the amounts of funds of legal entities and individuals attracted by issuing bills of exchange by credit institutions

    More Collapse –

    Data on the volume of attracted bank deposits

    More Collapse –

    Information on the amount of assets and equity (capital) of credit institutions

    More Collapse –

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: The government has suspended floating rates of duties on sunflower oil

    Translation. Region: Russian Federal

    Source: Government of the Russian Federation – Government of the Russian Federation –

    An important disclaimer is at the bottom of this article.

    Resolution of July 24, 2025 No. 1091

    Document

    Resolution of July 24, 2025 No. 1091

    The government is suspending the floating rates of export duties on sunflower oil and sunflower meal. This will increase the volume of shipments to foreign markets and support sunflower producers and processors. This decision was made at the suggestion of the Oil and Fat Union. It is especially relevant in anticipation of autumn field work.

    Floating rates of export customs duties on sunflower oil and meal were established by the Government from 2021 and 2022, respectively, in order to protect the domestic market from unjustified price increases. Thus, it was possible to stimulate the economic interest of producers in maintaining product supplies to the domestic market.

    Currently, the domestic market is fully supplied with sunflower oil. Therefore, the suspension will not affect the availability of sunflower oil for Russians.

    In June 2025, the export duty rate on sunflower oil was 7119.8 rubles per ton. In July – 4739.3 rubles per ton.

    In June 2025, the export duty rate on sunflower meal was 1,244.1 rubles per ton. In July 2025 – 1,054.4 rubles per ton.

    After the adoption of the Government Resolution, the rates were reset to zero. This measure will be in effect until August 31, 2025 inclusive.

    The signed document introduces changes toGovernment Resolution of April 6, 2021 No. 546.

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: Financial news: Individual performance indicators of credit institutions (by groups of credit institutions, ranked by asset size)

    Translation. Region: Russian Federal

    Source: Central Bank of Russia –

    An important disclaimer is at the bottom of this article.

    Information on funds attracted by credit institutions

    Volume of deposits from individuals attracted by credit institutions

    More Collapse –

    The volume of funds attracted by credit institutions from legal entities

    More Collapse –

    Volume of savings (deposit) certificates, bonds and bills issued by credit institutions

    More Collapse –

    Data on the amounts of bills of exchange discounted by credit institutions

    More Collapse –

    Data on the amounts of funds of legal entities and individuals attracted by issuing bills of exchange by credit institutions

    More Collapse –

    Data on the volume of attracted bank deposits

    More Collapse –

    Information on the amount of assets and equity (capital) of credit institutions

    More Collapse –

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI China: UN mission marks PLA anniversary in New York 2025-07-25 15:20:17 The Permanent Mission of China to the United Nations hosted a reception on Wednesday to mark the 98th anniversary of the founding of the Chinese People’s Liberation Army, which falls on Aug 1.

    Source: People’s Republic of China – Ministry of National Defense

    The Permanent Mission of China to the United Nations hosted a reception on Wednesday to mark the 98th anniversary of the founding of the Chinese People’s Liberation Army, which falls on Aug 1.

    UN Under-Secretary-General for Operational Support Atul Khare and other senior executives, as well as military and police advisers to the UN, attended the event, with about 200 guests in total. China’s permanent representative to the UN, Fu Cong, also attended the reception.

    This year marks the 80th anniversary of both the victory of the Chinese people in the War of Resistance Against Japanese Aggression (1931-45) and the triumph of the global community in the World Anti-Fascist War, as well as the 80th anniversary of the founding of the UN, said Yin Zhongliang, military adviser of China to the UN.

    “This year is also the 35th anniversary of China’s participation in UN peacekeeping operations,” Yin said. “The PLA has provided a solid foundation for safeguarding national sovereignty, regional security and common development.”

    Despite current global instability and intensifying geopolitical challenges, the Chinese armed forces “remains committed to a defensive national defense policy, and sets the goal of contributing to build a community with a shared future for humanity”, he said.

    China will continue to promote the Global Security Initiative, strengthen support for and participation in UN peacekeeping missions, and work hard to bring more confidence and hope to the cause of world peace and stability, he added.

    In his remarks at the event, Khare commended Chinese peacekeepers for their professionalism and dedication. “China has provided long-standing and robust support to the UN’s peacekeeping efforts,” he said, highlighting the important role of Chinese troops in some of the UN’s most challenging missions.

    Khare underscored China’s contributions to peacekeeping medical services, aviation support, and technological innovations, citing recent examples of Chinese efforts in South Sudan, Mali, and the Democratic Republic of Congo.

    He also emphasized China’s leadership in organizing peacekeeping-related training and its support for gender-sensitive and community-based medical care in mission areas.

    Continued cooperation

    Cheryl Pearce, acting UN military adviser in the Department of Peace Operations, who ensures that peace operations receive the military support they need, said Chinese personnel demonstrate professionalism and commitment, and are a credit to UN peacekeeping. She expressed anticipation for continued cooperation as the PLA approaches its centenary.

    Throughout the reception, guests also viewed videos highlighting the history and modernization of the PLA. Chinese military anthems were sung and a white paper on China’s peacekeeping contributions was on display.

    China is the largest troop contributor among the five permanent members of the UN Security Council and has deployed more than 50,000 peacekeepers to over 25 missions since the 1990s, according to the UN and China’s Ministry of National Defense.

    MIL OSI China News

  • MIL-OSI Asia-Pac: Statistics on Code on Access to Information for fourth quarter of 2024

    Source: Hong Kong Government special administrative region

    Statistics on Code on Access to Information for fourth quarter of 2024 
         The total number of requests received since the introduction of the Code in March 1995 and up to the end of December 2024 amounted to 134 124. Of these, 8 767 requests were subsequently withdrawn by the requestors, and 6 623 requests covered cases in which the bureaux/departments concerned did not hold the requested information or cannot confirm or deny the existence of information. As at December 31, 2024, 653 requests were still being processed by bureaux/departments.

         Among the 118 081 requests which covered information held by bureaux/departments and to which the bureaux/departments had responded, 114 706 requests (97.1 per cent) were met, either in full (111 597 requests) or in part (3 109 requests), and 3 375 requests (2.9 per cent) were refused.Issued at HKT 15:30

    NNNN

    MIL OSI Asia Pacific News

  • MIL-OSI China: ​Internet industry conference shines light on future development

    Source: People’s Republic of China – State Council News

    The opening ceremony of the 24th China Internet Conference in Beijing, July 23, 2025. [Photo by Liu Sitong/China.org.cn]

    The 24th China Internet Conference opened in Beijing on July 23, with industry experts gathering to share their thoughts on the development and future of the internet sector. 

    At the event’s opening ceremony, Wu Hequan, former vice president of the Chinese Academy of Engineering, said the internet sector has entered an era of development driven by artificial intelligence (AI). As such, he said that the industry should rely on AI agents, instead of generative AI, to create new application scenarios in order to realize commercial success. 

    Wu added that “AI for Internet” and “Internet for AI” will empower new quality productive forces and drive the transformation of business formats; however, related applications still require further innovations in technology and to business models. 

    Tang Ke, deputy general manager of China Telecom, spoke about the profound upgrading of AI-related computing power, data, algorithms, applications and security technology amid the new round of sci-tech revolution and industrial transformation that has reshaped the industrial ecosystem. 

    To ride this trend, Tang explained that China Telecom has been innovating technologies and fully developing its strength in AI. In addition, the company is building smart cloud capabilities, exploring computing power coordination to improve efficiency, and enriching AI applications while ensuring security. 

    Cheng Jianjun, vice president of China Mobile, said as a new driving force for digital economy, computing power has been growing faster than they could have been imagined. He explained that the company has so far established 13 smart computing centers and are currently building several super-large smart computing centers. 

    He added that the company has also invested in quantum technology, including a quantum computing cloud platform that has connected 500 universities and colleges and incubated a dozen enterprises. Meanwhile, to serve the development of low-altitude economy, the company is building a digital infrastructure network enabling integrated sensing and communication.

    Hao Liqian, deputy general manager of China Unicom, spoke about his company’s efforts to accelerate the integrated development of computing power, network, digital technology and large-scale models, and their focus on offering AI services that are convenient, efficient, practical, safe and inclusive. By innovating services, the company has also helped various regions such as Beijing and Chongqing to upgrade their government service hotlines to go smart. 

    Zhu Zheng, senior vice president and chief development officer of the popular e-commerce company Pinduoduo, introduced a program they launched in April. The company plans to invest 100-billion-yuan worth of resources over the next three years to improve the e-commerce ecosystem and help businesses on their platform transform and upgrade. 

    According to Zhu, the company has so far connected 1,000 agricultural areas and helped 16 million agricultural workers to participate in the digital economy. Meanwhile, the firm also provides digital services for manufacturing enterprises regarding product design and development, production and branding. 

    Gao Ji, chief executive officer of Chinese semiconductor provider HiSilicon, said that the audio video industry is highly relevant to the development of the internet sector. The company aims to provide an improved consumer experience with audio and video products. 

    Han Yonggang, vice president of China’s leading cybersecurity company QAX, said the company has aligned cybersecurity capabilities with digital development. He said that AI security means ensuring safe use of AI technology as well as using AI as a new driving force to enhance our security capabilities. He called for cybersecurity management and technology to be better connected, ensuring cybersecurity management with systematic technical support. 

    The China Internet Conference was organized by the Internet Society of China and will run until July 25.

    MIL OSI China News

  • MIL-OSI Banking: BSTDB Backs Renewable Energy Expansion in Bulgaria and Romania with €40 Million Loan to Renalfa IPP

    Source: Black Sea Trade and Development Bank

    Press Release | 24-Jul-2025

    Joint €315 million international financing to accelerate clean energy investments

    The Black Sea Trade and Development Bank (BSTDB) is providing up to €40 million loan to support the development, hybridization, and expansion of Renalfa IPP’s renewable energy assets in Bulgaria and Romania. The financing forms part of a broader €315 million financing package secured from leading development finance institutions and commercial banks, including the European Bank for Reconstruction and Development (EBRD), Kommunalkredit Austria AG, OTP Hungary, NLB Slovenia, and UniCredit BulBank.

    The funds will enable Renalfa IPP to upgrade its portfolio of renewable energy and battery energy storage systems (BESS), contributing to the decarbonization of Bulgaria’s and Romania’s power systems. The project will help diversify the countries’ energy mix, enhance energy security, and accelerate their transition to low-carbon economies. The BSTDB financing will also help catalyze further private and public sector investments, generate employment during both the construction and operation phases, and create long-term value for local communities. The operation represents a major step forward in the region’s transition toward cleaner, more secure, and sustainable energy systems.

    “This investment marks an important milestone in BSTDB’s efforts to support the clean energy transition in the Black Sea region,” said Dr. Serhat Köksal, BSTDB President.  “By backing the development of solar, wind, and battery storage infrastructure in Bulgaria and Romania, we are strengthening the resilience and competitiveness of their electricity sectors. The operation will play a key role in addressing the countries’ growing energy demands, while also reducing carbon emissions and supporting their commitments to climate goals. Moreover, it aligns closely with BSTDB’s Climate Strategy and reinforces our commitment to financing sustainable infrastructure and regional growth.”

    Ivo Prokopiev, CEO of Renalfa IPP, commented: “The successful raising of growth funding is an important milestone for Renalfa IPP and for our whole group. It proves the competitiveness of our integrated model for developing, investing and operating large hybrid assets. The early implementation of long duration co-located BESS allows Renalfa IPP to start offering green baseload products to market in CEE for the first time. We are proud, together with our partners from RGreen, to be on the frontier of energy transition not only in CEE, but in the whole EU.”

    Renalfa IPP is a leading independent power producer based in Vienna, specializing in the development, construction, and operation of renewable energy projects across Central and Eastern Europe. As an established platform with strong business model capabilities, Renalfa IPP works across the full value chains from project origination to asset operation. The company focuses on solar, wind, and Battery Energy Storage Systems (BESS), supporting the region’s transition to a sustainable and low-carbon energy future. Renalfa IPP is a joint venture between Renalfa Solarpro Group and RGREEN INVEST. 

    Renalfa Solarpro Group is a Vienna based clean energy and e-mobility investment group with a focus on renewable energy generation assets. Renalfa Solarpro is an established platform with strong business model capabilities, working across the full solar PV, wind, and BESS value chains from project origination to asset operation.

    RGREEN INVEST is an independent French mission-driven investment management company committed to helping investors channel their capital towards financing projects dedicated to accelerating the energy transition, mitigation, and adaptation to climate change.

    https://www.renalfa.com

    https://www.rgreeninvest.com

     

    The Black Sea Trade and Development Bank (BSTDB) is an international financial institution established by Albania, Armenia, Azerbaijan, Bulgaria, Georgia, Greece, Moldova, Romania, Russia, Türkiye, and Ukraine. The BSTDB headquarters are in Thessaloniki, Greece. BSTDB supports economic development and regional cooperation by providing loans, credit lines, equity and guarantees for projects and trade financing in the public and private sectors in its member countries. The authorized capital of the Bank is EUR 3.45 billion. For information on BSTDB, visit www.bstdb.org.

     

    Contact: Haroula Christodoulou

    : @BSTDB

    MIL OSI Global Banks

  • Vice-Presidential election: Election Commission appoints returning officer and assistants

    Source: Government of India

    Source: Government of India (4)

    The Election Commission of India (ECI) has appointed the Secretary General of the Rajya Sabha as the returning officer for the upcoming Vice-Presidential election. The decision follows established convention, with the role rotating between the Secretaries General of the Lok Sabha and Rajya Sabha.

    The appointments were made under Section 3 of the Presidential and Vice-Presidential Elections Act, 1952, in consultation with the Union Ministry of Law and Justice and with the consent of the Deputy Chairman of the Rajya Sabha.

    In addition to the returning officer, the ECI has appointed Garima Jain, Joint Secretary, and Vijay Kumar, Director, both from the Rajya Sabha Secretariat, as assistant returning officers for the election.

    The formal Gazette notification is being issued separately.

    The Vice-Presidential election is conducted under Article 324 of the Constitution and governed by the Presidential and Vice-Presidential Elections Act, 1952, along with the accompanying rules from 1974.

    On Wednesday, the ECI initiated the process to conduct Vice-Presidential election, two days after Jagdeep Dhankhar resigned from the post citing health reasons.

    “The Election Commission of India, under Article 324, is mandated to conduct the election to the office of the Vice President of India. The election to the office of the Vice President of India is governed by The Presidential and Vice-Presidential Elections Act, 1952 and the rules made thereunder, namely The Presidential and Vice-Presidential Elections Rules, 1974,” said the ECI.

    Under Article 66(1) of the Constitution, the Vice-President is elected by an electoral college comprising members of both the Lok Sabha and the Rajya Sabha, using the system of proportional representation by means of a single transferable vote, with voting conducted by secret ballot.

    Dhankhar’s tenure was originally set to end on August 10, 2027.

  • India-UK FTA a “landmark economic achievement”: TPCI

    Source: Government of India

    Source: Government of India (4)

    The Trade Promotion Council of India (TPCI) has termed the India-UK Free Trade Agreement (FTA) a “landmark economic achievement,” saying it will open up new opportunities for Indian exporters across key sectors.

    Calling the deal “visionary,” TPCI Chairman Mohit Singla said the agreement supports the development of globally competitive Indian brands, while advancing rural growth and India’s integration into global value chains.

    India’s total trade with the United Kingdom touched $23.1 billion in FY2024–25, with exports rising 12.4 per cent to $14.5 billion. Imports grew marginally by 2.3 per cent to $8.6 billion, resulting in a trade surplus of $5.9 billion.

    The FTA is expected to drive agricultural exports, with zero-duty access granted to over 95 per cent of Indian farm and processed food products. These include fruits, vegetables, cereals, coffee, tea, spices, oilseeds, alcoholic beverages, and ready-to-eat items. According to TPCI, this could push agri-exports to the UK up by over 20 per cent in the next three years.

    The seafood industry is also set to benefit, with Indian exporters gaining tariff parity with EU countries like Germany and the Netherlands. The UK’s $5.4 billion marine market will now be accessible duty-free, potentially benefiting fisherfolk in states such as Andhra Pradesh, Odisha, Kerala, Gujarat, and Tamil Nadu.

    In addition to goods, the FTA also addresses mobility and services. Ashish Kumar Chauhan, MD and CEO of the National Stock Exchange (NSE), said Indian professionals working in the UK will be exempt from paying social security tax for up to three years — an annual saving estimated at ₹4,000 crore. He also said the new visa framework would allow for longer professional stays, adding that the agreement sets a precedent for FTAs with other major economies such as the US, EU, and Japan.

    The engineering sector has also welcomed the agreement. EEPC India noted that the UK, India’s sixth-largest engineering export destination, posted 11.7 per cent growth in trade during 2024–25. With the FTA eliminating tariffs of up to 18 per cent on key engineering items, exports are expected to gain further traction.

    EEPC India Chairman Pankaj Chadha said the deal could help double engineering exports to the UK to over $7.5 billion by 2029–30. “It is a strategic breakthrough that will energise the sector, particularly MSMEs, and strengthen India’s role in global supply chains,” he said.

    —IANS

  • PM Modi to unveil development projects worth over ₹4800 crore in Tamil Nadu

    Source: Government of India

    Source: Government of India (4)

    Prime Minister Narendra Modi is set to embark on a two-day visit to Tamil Nadu on July 26 and 27, during which he will lay the foundation stone, inaugurate, and dedicate to the nation a wide array of development projects valued at over ₹4800 crore. His visit underscores the government’s commitment to enhancing infrastructure, regional connectivity, and cultural heritage in southern India.

    Upon his return from state visits to the United Kingdom and the Maldives, the Prime Minister will head directly to Tuticorin on the evening of July 26. There, he will inaugurate several key infrastructure projects designed to improve connectivity, logistics, energy efficiency, and overall quality of life in Tamil Nadu.

    One of the major highlights of his visit will be the inauguration of the New Terminal Building at Tuticorin Airport, constructed at a cost of around ₹450 crore. Spanning 17,340 square meters, the terminal is designed to handle 1,350 passengers during peak hours and up to 20 lakh annually, with provisions for future expansion. Equipped with energy-efficient systems and sustainable facilities, it aims to achieve a GRIHA-4 sustainability rating, promoting eco-friendly aviation infrastructure and boosting tourism and commerce in the region. GRIHA (Green Rating for Integrated Habitat Assessment) is a system for evaluating green buildings. It facilitates the assessment of a building’s performance based on nationally accepted standards or benchmarks.

    To significantly improve travel and trade, the Prime Minister will dedicate two strategically significant projects to the nation.
    The rail sector will also see significant upgrades aimed at reducing travel time and boosting freight movement.

    PM Modi will dedicate two major highway projects. The first is the 4-laning of the 50 km Sethiyathope–Cholapuram section of NH-36, developed at a cost exceeding ₹2,350 crore. This project includes bypasses, bridges, and flyovers and is expected to reduce travel time by 45 minutes between key delta districts. The second project involves the 6-laning of a 5.16 km stretch on NH-138, linking Tuticorin Port and surrounding industrial areas. Built at around ₹200 crore, it is expected to reduce logistics costs and enhance port-led industrial development.

    Further strengthening port infrastructure, the Prime Minister will inaugurate the North Cargo Berth–III at V.O. Chidambaranar Port. With a capacity of 6.96 million metric tonnes per annum (MMTPA), the ₹285 crore facility will meet rising demand for dry bulk cargo and improve cargo handling efficiency.

    PM Modi will dedicate to the nation three major rail infrastructure projects. These include the electrification of the 90 km Madurai–Bodinayakkanur section, the doubling of the 21 km Nagercoil Town–Kanniyakumari section, and doubling of shorter but critical links such as Aralvaymozhi–Nagercoil Junction and Tirunelveli–Melappalayam. Together, these upgrades will reduce travel time, enhance freight and passenger movement, and strengthen links between Tamil Nadu and neighboring Kerala.

    The Prime Minister will also lay the foundation stone for the Inter-State Transmission System (ISTS) for Kudankulam Nuclear Power Plant Units 3 and 4. The ₹550 crore project includes a high-capacity 400 kV double-circuit transmission line, enhancing the national grid and ensuring reliable clean energy supply to Tamil Nadu and other states.

    On July 27, PM Modi will travel to Tiruchirappalli to take part in the Aadi Thiruvathirai Festival at the historic Gangaikonda Cholapuram Temple. As part of the celebration, he will release a commemorative coin honoring Emperor Rajendra Chola I, one of India’s most iconic rulers, and mark the 1,000th anniversary of his maritime expedition to Southeast Asia.

    The event will also commemorate the beginning of the construction of the Gangaikonda Cholapuram temple, a marvel of Chola architecture and a UNESCO World Heritage Site. Rajendra Chola I, who ruled from 1014 to 1044 CE, is remembered for his expansive naval expeditions and for establishing a capital that embodied spiritual devotion and administrative excellence.

    This year’s Aadi Thiruvathirai holds special significance, as it aligns with Rajendra Chola’s birth star, Thiruvathirai, which began on July 23. The celebration also honors Tamil Shaiva Bhakti traditions and the legacy of the 63 Nayanmars, further highlighting the region’s cultural and religious heritage.

     

  • India successfully tests UAV-Launched Precision Guided Missile in Andhra Pradesh

    Source: Government of India

    Source: Government of India (4)

    In a boost to India’s indigenous defence capabilities, the Defence Research and Development Organisation (DRDO) on Friday successfully conducted flight trials of the UAV-Launched Precision-Guided Missile (ULPGM)-V3 at the National Open Area Range (NOAR) in Kurnool, Andhra Pradesh.

    In a post on X, Defence Minister Rajnath Singh announced the achievement, “In a major boost to India’s defence capabilities, DRDO has successfully carried out flight trials of UAV Launched Precision Guided Missile (ULPGM)-V3 in the National Open Area Range (NOAR), test range in Kurnool, Andhra Pradesh. Congratulations to DRDO and the industry partners, DcPPs, MSMEs and Start-ups for the development and successful trials of the ULPGM-V3 system. This success proves that the Indian industry is now ready to absorb and produce critical Defence Technologies.”

    While detailed specifications of the ULPGM-V3 remain classified, its development reflects a strategic progression in India’s guided missile programme. The earlier ULPGM-V2, developed by DRDO’s Terminal Ballistics Research Laboratory (TBRL), featured multiple warhead configurations. The V3 variant, believed to incorporate advanced features such as imaging infrared (IIR) seekers and dual-thrust propulsion systems, builds on this legacy and was previewed during Aero India 2025.

    The successful trial underscores India’s growing emphasis on unmanned precision-strike capabilities – an essential element of modern warfare. ULPGM systems are designed to be lightweight, highly accurate, and compatible with a range of aerial platforms, offering critical operational flexibility in dynamic combat environments.

    The choice of NOAR in Kurnool for the trial aligns with DRDO’s strategy of leveraging this facility to test advanced technologies. In recent months, the range has hosted successful trials of high-energy laser-based Directed Energy Weapons (DEWs), including systems that neutralized fixed-wing UAVs and swarm drones – highlighting India’s expanding high-tech defence testing infrastructure.

    (IANS)

  • MIL-OSI Russia: Chinese and Russian think tanks should strengthen cooperation – Alexander Lukin

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    ZHENGZHOU, July 25 (Xinhua) — In the current complex and changing international situation, think tanks in Russia and China should strengthen cooperation, said Alexander Lukin, research director of the Institute of China and Modern Asia at the Russian Academy of Sciences, on the sidelines of the SCO Media and Think Tank Summit, which is being held from July 23 to 27 in Zhengzhou, capital of Henan Province, central China.

    Many scientific centers in Russia are already working on this, including the Institute of China and Modern Asia of the Russian Academy of Sciences. Analytical centers of China and Russia are strengthening cooperation in such areas as economics, international security, world politics, etc., added A. Lukin.

    “Strengthening cooperation between analytical centers of China and Russia, first of all, contributes to mutual understanding between the peoples, scientists and governments of our countries,” said A. Lukin. “In addition, such cooperation helps to strengthen and improve the quality of analytics and scientific information of both countries, and its promotion both within their countries and in the world as a whole.”

    A. Lukin noted that China’s economic development at the end of the 20th and beginning of the 21st centuries is a completely unique achievement in the history of mankind. Its uniqueness lies in the fact that such a combination of these methods was found that was suitable for such a huge country as China.

    According to him, this successful experiment deserves a thorough study, which is what researchers in many countries around the world are doing. -0-

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: China’s Yunnan Province Donates Solar Street Lights to Myanmar

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    YANGON, July 25 (Xinhua) — A handover ceremony for solar-powered street lights donated by China was held in Yangon on Thursday.

    40 solar street lamps donated by the Yunnan Provincial People’s Association for Friendship with Foreign Countries were handed over to the head of Taketa Township.

    The move aims to improve safety during nighttime travel and reduce energy costs, and has also helped strengthen the friendship between China and Myanmar. –0–

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: Chinese company launches pilot autonomous taxi service in Saudi Arabia

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    RIYADH, July 25 (Xinhua) — Chinese technology company WeRide on Wednesday launched a pilot autonomous taxi service under the Robotaxi brand in Saudi Arabia.

    Several dozen vehicles serve King Khalid International Airport and several key areas of Riyadh, including major highways and select destinations in the city centre.

    WeRide said it expects to launch full commercial operations by the end of 2025.

    “The pilot launch of the autonomous taxi service reflects the Kingdom’s vision and strategic investment in the future of mobility,” said Saudi Arabia’s Minister of Transport and Logistics Services Saleh bin Nasser Al Jasser. “This step reinforces our commitment to fostering innovation, adopting cutting-edge technologies, and creating a globally competitive, efficient and sustainable transport sector that supports economic growth and improves quality of life for all,” he added.

    “The kingdom’s forward-thinking approach and commitment to innovation make it a natural market for our regional expansion,” said Li Xuan, WeRide’s chief financial officer and head of international. –0–

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: 166 trucks with humanitarian aid entered Gaza overnight – Egyptian source

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    CAIRO, July 25 (Xinhua) — About 166 trucks carrying humanitarian aid entered the Gaza Strip on the night from Wednesday to Thursday, Egyptian Al-Qahira Al-Ikhbariya TV reported, citing an anonymous source in the security forces.

    According to him, trucks carrying humanitarian aid entered the besieged enclave through the Zikim and Kerem Shalom /Kerem Abu Salem/ border crossings.

    The aid shipment included flour, food and medicine, the source said. “Egypt has stepped up its efforts with all international parties to deliver more aid to the Gaza Strip during this period,” he added.

    The humanitarian situation in the Palestinian enclave continues to deteriorate, with Israel cutting off supplies and food to Gaza after the first phase of the ceasefire agreement with Hamas expired in January.

    The UN Office for the Coordination of Humanitarian Affairs (OCHA) warned on Wednesday that hunger in the sector is at its worst ever, with aid workers and those they help exhausted, aid agencies say.

    A new round of indirect talks between Hamas and Israel resumed earlier this month in the Qatari capital Doha amid international efforts to end the conflict and resume humanitarian aid deliveries.

    Since October 2023, the Israeli military campaign has killed more than 59,210 Palestinians in the enclave and injured more than 143,040, according to Gaza’s medical authorities. –0–

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: China’s domestically produced civil search and rescue aircraft Xinzhou-60 completes maiden test flight

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    BEIJING, July 25 (Xinhua) — China’s independently developed civil search and rescue aircraft MA60 successfully completed its maiden flight, officially starting the flight test and validation stage, according to Aviation Industry Corporation of China (AVIC), a leading Chinese aircraft maker.

    AVIC announced on Thursday that the aircraft successfully completed its daytime testing tasks during the one-hour and 20-minute test flight and landed safely at the airport in Xi’an, capital of northwest China’s Shaanxi Province.

    The new aircraft belongs to the domestically produced Xinzhou family of multi-role aircraft.

    According to AVIC experts, problems such as slow response times and limited coverage of the search system have long hampered the country’s ability to conduct maritime search and rescue operations over vast distances and in challenging conditions.

    Designed for search and rescue, terrain reconnaissance and personnel transportation, the Xinzhou-60 is designed to cover a wide range of application scenarios. It can perform search and rescue missions at sea, in high-altitude areas and in areas affected by natural disasters such as earthquakes and floods.

    The specialized aircraft is expected to greatly enhance China’s maritime search and rescue capabilities, significantly improving response speed and coverage area, AVIC said.

    The Xinzhou-60 aircraft development project was officially launched in December 2021. The production and delivery of major components was completed in December 2024, followed by final assembly and delivery work in May 2025. -0-

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Russia: Global investors’ confidence in China market is growing

    Translation. Region: Russian Federal

    Source: People’s Republic of China in Russian – People’s Republic of China in Russian –

    An important disclaimer is at the bottom of this article.

    Source: People’s Republic of China – State Council News

    Global sovereign wealth funds are increasing their China holdings, optimistic about China’s advances in digital technology, renewable energy and advanced manufacturing, according to Invesco’s latest Global Sovereign Wealth Management 2025 research report.

    About 60% of Middle Eastern sovereign wealth funds plan to increase their Chinese holdings over the next five years, while sovereign wealth funds from Asia-Pacific, Africa and North America have also said they will increase their investment in the Chinese market.

    Factors contributing to the increase in investment include high returns in the Chinese market, diversification of investment portfolios and improved Chinese policies on market access for foreign investors.

    Respondents acknowledged China’s favorable policies and noted that China’s innovation leadership in science and technology has increased, with digital technology, advanced manufacturing, clean energy, and medicine and health care being the most attractive areas.

    Please note: This information is raw content obtained directly from the source of the information. It is an accurate report of what the source claims and does not necessarily reflect the position of MIL-OSI or its clients.

    .

    MIL OSI Russia News

  • MIL-OSI Asia-Pac: 101k private flats projected

    Source: Hong Kong Information Services

    The projected private flat supply for the next three to four years is 101,000 units, 4,000 lower than the previous estimate.

    The Housing Bureau today said there were 27,000 unsold units in completed projects at the end of June.

    There were also 64,000 units under construction, excluding those pre-sold by developers; and 10,000 units from disposed sites where construction may start anytime.

    The number of flats under construction in the second quarter was 2,500, while 4,600 units were completed during the period.

    MIL OSI Asia Pacific News

  • MIL-OSI Australia: Press conference, Calamvale, Queensland

    Source: Australian Parliamentary Secretary to the Minister for Industry

    Jim Chalmers:

    The purpose of economic reform is to boost incomes and lift living standards over time. When we came to office, living standards were in free fall, inflation was much higher and galloping, real wages were falling, interest rates had already started to come up – and we’ve been turning things around. We’ve got inflation much lower, sustainably within the Reserve Bank’s target band, real wages are growing again, interest rates have started to come down, unemployment is low, we’ve delivered a couple of surpluses and we’ve got the Liberal debt down as well.

    We’ve made a lot of progress together in our economy, but we know that there’s more work to do. We’ve got a big agenda that we are delivering, that we are rolling out. But we know that at a time when people are still under pressure, the global economic environment is uncertain and when we’ve got these persistent structural issues in our economy as well, we’ve got more work to do and that’s what our efforts on economic reform are all about.

    Our Economic Reform Roundtable is all about making our economy more productive and more resilient and our budget more sustainable at the same time. Now, these are long‑standing issues in our economy and there’s no quick fix. We have an agenda that we’re rolling out, and we are looking to build consensus about next steps when it comes to our economy.

    Now, when it comes to the range of views which have been provided, especially in the last couple of days, whether it be from the union movement, the business community, the Productivity Commission, there have been a range of proposals put to us. I know that the Member for Wentworth and the federal parliament is hosting a tax reform discussion today as well.

    I want to make it really clear – we welcome ideas on the future of our economy from every corner of our economy and every part of our communities. This is a good thing to see the kind of engagement and interest that we’ve seen in the government’s Economic Reform Roundtable and all of the processes which surround it. We don’t expect there to be a unanimous view, but we are seeking common ground. We do welcome ideas from all parts of our country and we’re very encouraged by the level of interest and engagement that we are seeing.

    When it comes to the Productivity Commission report released overnight, I wanted to make a couple of points specifically about that. The Productivity Commission makes it really clear that this challenge in our economy has not been just a feature of our economy the last couple of years, but for the last couple of decades. Our productivity challenge is a long‑standing challenge. The weakest decade for productivity growth in the last 60 years was the decade that our political opponents presided over. So, this challenge has been in our economy for some time.

    There are no quick fixes and we want to work with business and unions and the community more broadly to turn that around over time. Making our economy more productive is one of the most important ways that we can boost incomes and lift living standards over time, and that’s why it’s such a priority for us. Our priorities are to make our economy more productive, to make our economy more resilient in the face of all this global uncertainty, and also to make our budget more sustainable. At the same time, the Productivity Commission has provided some thinking to help us work through these issues. We also welcome the input from unions and businesses and others. I suspect that there will be more of this between now and the Roundtable next month, and that’s a very good thing. Happy to take a couple of questions.

    Journalist:

    Minister, I’ve just got a few questions from our journos in Canberra. On productivity, business and unions are already taking shots at each other in the media over the Productivity Roundtable. Are you worried that the process is becoming unconstructive already?

    Chalmers:

    Not at all. There’ll be a range of views about our productivity challenge and that’s a good thing. We welcome engagement and interest and ideas from unions, from business, from the Productivity Commission, from the community sector and from others. It’s a good thing in a country like ours that we can tease out our differences and seek common ground and that’s what we’re seeing right now. This is precisely why we’re seeking to bring people together. Not because we expect everyone to have a unanimous view. But because everyone’s got an interest in strengthening our economy and strengthening our budget, making our economy more productive and more resilient, lifting living standards and boosting incomes.

    Every Australian has an interest in that. Not every Australian will have a unanimous view, but this is our best effort to seek common ground around these big, persistent structural challenges in our economy. We think it’s a good thing that that conversation that people are engaged in is robust. We think it’s a good thing that people are being blunt and upfront about their views. I think that gives us the best possible chance of working out if there’s common ground and where that common ground might exist.

    Journalist:

    How does Queensland benefit from the opening of [INAUDIBLE] beef imports from the US?

    Chalmers:

    Well, this has been a long standing process that has been underway. It’s a scientific process that involves experts and scientists and it makes sure that our arrangements are up to scratch. I see that there’s a lot of commentary around this in the last day or 2. I know that our political opponents want to play their usual low‑rent politics over it but this is a long‑standing scientific process. It’s coming to a conclusion and it’s all about making sure that we have the best arrangements based on the best scientific advice.

    Journalist:

    The ACTU says that workplace managers are dragging down the nation’s productivity. Is that a view you share?

    Chalmers:

    I think it’s obvious that when it comes to decisions taken by managers and by boards and by others, obviously, that has implications for productivity. I think it would be unusual in the extreme if the ACTU representing Australian workers weren’t able to make that view public. And as I said before, and in answer to your colleague’s question here, I think it’s a good thing.

    Whether it’s the unions, the business community, the PC or others, people should be free to express their views about the best way forward when it comes to making our economy more productive. Obviously, decisions taken by managers and by boards and by others are relevant here to the productivity challenge and I think the ACTU should be able to make their views public.

    Journalist:

    Hoping to ask you a question about the ABC’s Four Corners story about the ATO and Paul Keating’s company. Are you confident that ordinary taxpayers would have the same level of access and the opportunity to get a similar outcome on a tax write‑off as the former Prime Minister Paul Keating?

    Chalmers:

    Well, first of all, I want to make it clear that the first I knew about that decision was when I read it on the ABC website. It’s not something that I was involved in or aware of. In fact, the decision, as I understand it, was made about a decade ago in 2015. That’s 3 treasurers ago, 4 if you include Scott Morrison’s sneaky second stint as Treasurer. So, a long time ago under a government of a different persuasion and a few treasurers ago.

    The ATO takes these decisions independently, that’s how the system works, and treasurers of both political persuasions don’t make commentary on the tax affairs of individuals or individual companies. These decisions are rightly taken independently by the ATO. They have their own processes when it comes to reviewing and considering appeals and feedback that they get from different taxpayers. And that is appropriately a matter for them.

    Journalist:

    Will you be contacting them though, and asking them for a full explanation?

    Chalmers:

    Look, I speak regularly with the Commissioner of Tax Rob Heferen. I appointed him not that long ago. We met not that long ago, we catch up relatively frequently, but it’s not for me to second‑guess decisions taken 10 years ago under other treasurers and other tax commissioners. There are good reasons why the ATO takes those sorts of decisions independently, free of political involvement or interference.

    Journalist:

    Do you think that Glencore is bluffing when it says it’s going to close its copper smelter? And if it isn’t bluffing, what is the federal government doing to protect 17,000 indirect jobs through the chain of supply in North Queensland?

    Chalmers:

    This is a very anxious time for the workers of North Queensland and North West Queensland as well. Very anxious time. The Industry Minister, Tim Ayres, gave an update to the Senate yesterday – as I understand it – on these matters. Our priority is to try and find a way through. Minister Ayres, I think, is convening the major players involved here in the next few weeks to try and find a way through.

    I’m not interested in second guessing the explanations that the company might be providing. I’m interested in trying to find a way through, so I work with Tim Ayres. He’s been very focused on this. We’re obviously very aware of it. It’s obviously an anxious time for all of the workers and communities involved and so if we can find a way through, we will. Tim Ayres is bringing people together to try and see what the next steps could be.

    Journalist:

    Minister, France has announced it will recognise Palestine at the UN General Assembly in September, would that influence Australia’s position?

    Chalmers:

    That’s a matter for the French government. Our Australian position is very clear. We’ve called for an immediate end of the war in Gaza and we support an enduring 2 state solution as the best pathway out of this endless cycle of violence. So the Australian position is clear. I know that Penny Wong will be speaking later on today in the context of the AUKMIN ministers meeting in Sydney, so she might have more to add about that then.

    Journalist:

    Ms Spender is hosting her own tax roundtable today where halting the $3 million super tax will be discussed. Would you be open to hearing those similar sorts of views from that roundtable in your own discussions and roundtable?

    Chalmers:

    I’ve been consulting on that issue for 2 and a half years now. We announced that decision, that policy, 2 and a half years ago. We’ve done 3 rounds of formal consultation, there’s been Treasury‑led technical roundtables, stakeholder roundtables, bilateral engagement, so we’ve been engaging and consulting on that for years now. I know that Allegra has a view about it and she has a right to express that view, as do people participating at the roundtable. I want to say this more broadly, I think it’s absolutely terrific that Allegra Spender is bringing people together as part of the tax component of this Economic Reform Roundtable.

    The Economic Reform Roundtable, as I said, is about productivity, resilience and budget sustainability and obviously, tax has a role to play in all 3 of those things so I think it’s a really good thing that Allegra is bringing those experts together in Canberra today. As I understand it, I will obviously listen to and respect the views put forward around that table today in Canberra. My position on making these generous tax concessions – still generous, still concessional – but fairer and more sustainable is well known, well established.

    Thanks very much.

    Journalist:

    Thank you very much, Treasurer.

    MIL OSI News

  • MIL-OSI Economics: ToolShell: a story of five vulnerabilities in Microsoft SharePoint

    Source: Securelist – Kaspersky

    Headline: ToolShell: a story of five vulnerabilities in Microsoft SharePoint

    On July 19–20, 2025, various security companies and national CERTs published alerts about active exploitation of on-premise SharePoint servers. According to the reports, observed attacks did not require authentication, allowed attackers to gain full control over the infected servers, and were performed using an exploit chain of two vulnerabilities: CVE-2025-49704 and CVE-2025-49706, publicly named “ToolShell”. Additionally, on the same dates, Microsoft released out-of-band security patches for the vulnerabilities CVE-2025-53770 and CVE-2025-53771, aimed at addressing the security bypasses of previously issued fixes for CVE-2025-49704 and CVE-2025-49706. The release of the new, “proper” updates has caused confusion about exactly which vulnerabilities attackers are exploiting and whether they are using zero-day exploits.

    Kaspersky products proactively detected and blocked malicious activity linked to these attacks, which allowed us to gather statistics about the timeframe and spread of this campaign. Our statistics show that widespread exploitation started on July 18, 2025, and attackers targeted servers across the world in Egypt, Jordan, Russia, Vietnam, and Zambia. Entities across multiple sectors were affected: government, finance, manufacturing, forestry, and agriculture.

    While analyzing all artifacts related to these attacks, which were detected by our products and public information provided by external researchers, we found a dump of a POST request that was claimed to contain the malicious payload used in these attacks. After performing our own analysis, we were able to confirm that this dump indeed contained the malicious payload detected by our technologies, and that sending this single request to an affected SharePoint installation was enough to execute the malicious payload there.

    Our analysis of the exploit showed that it did rely on vulnerabilities fixed under CVE-2025-49704 and CVE-2025-49706, but by changing just one byte in the request, we were able to bypass those fixes.

    In this post, we provide detailed information about CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771, and one related vulnerability. Since the exploit code is already published online, is very easy to use, and poses a significant risk, we encourage all organizations to install the necessary updates.

    The exploit

    Our research started with an analysis of a POST request dump associated with this wave of attacks on SharePoint servers.

    Snippet of the exploit POST request

    We can see that this POST request targets the “/_layouts/15/ToolPane.aspx” endpoint and embeds two parameters: “MSOtlPn_Uri” and “MSOtlPn_DWP”. Looking at the code of ToolPane.aspx, we can see that this file itself does not contain much functionality and most of its code is located in the ToolPane class of the Microsoft.SharePoint.WebPartPages namespace in Microsoft.SharePoint.dll. Looking at this class reveals the code that works with the two parameters present in the exploit. However, accessing this endpoint under normal conditions is not possible without bypassing authentication on the attacked SharePoint server. This is where the first Microsoft SharePoint Server Spoofing Vulnerability CVE-2025-49706 comes into play.

    CVE-2025-49706

    This vulnerability is present in the method PostAuthenticateRequestHandler, in Microsoft.SharePoint.dll. SharePoint requires Internet Information Services (IIS) to be configured in integrated mode. In this mode, the IIS and ASP.NET authentication stages are unified. As a result, the outcome of IIS authentication is not determined until the PostAuthenticateRequest stage, at which point both the ASP.NET and IIS authentication methods have been completed. Therefore, the PostAuthenticateRequestHandler method utilizes a series of flags to track potential authentication violations. A logic bug in this method enables an authentication bypass if the “Referrer” header of the HTTP request is equal to “/_layouts/SignOut.aspx”, “/_layouts/14/SignOut.aspx”, or “/_layouts/15/SignOut.aspx” using case insensitive comparison.

    Vulnerable code in PostAuthenticateRequestHandler method (Microsoft.SharePoint.dll version 16.0.10417.20018)

    The code displayed in the image above handles the sign-out request and is also triggered when the sign-out page is specified as the referrer. When flag6 is set to false and flag7 is set to true, both conditional branches that could potentially throw an “Unauthorized Access” exception are bypassed.

    Unauthorized access checks bypassed by the exploit

    On July 8, 2025, Microsoft released an update that addressed this vulnerability by introducing additional checks to detect the usage of the “ToolPane.aspx” endpoint with the sign-out page specified as the referrer.

    CVE-2025-49706 fix (Microsoft.SharePoint.dll version 16.0.10417.20027)

    The added check uses case insensitive comparison to verify if the requested path ends with “ToolPane.aspx”. Is it possible to bypass this check, say, by using a different endpoint? Our testing has shown that this check can be easily bypassed.

    CVE-2025-53771

    We were able to successfully bypass the patch for vulnerability CVE-2025-49706 by adding just one byte to the exploit POST request. All that was required to bypass this patch was to add a “/” (slash) to the end of the requested “ToolPane.aspx” path.

    Bypass for CVE-2025-49706 fix

    On July 20, 2025, Microsoft released an update that fixed this bypass as CVE-2025-53771. This fix replaces the “ToolPane.aspx” check to instead check whether the requested path is in the list of paths allowed for use with the sign-out page specified as the referrer.

    CVE-2025-53771 fix (Microsoft.SharePoint.dll version 16.0.10417.20037)

    This allowlist includes the following paths: “/_layouts/15/SignOut.aspx”, “/_layouts/15/1033/initstrings.js”, “/_layouts/15/init.js”, “/_layouts/15/theming.js”, “/ScriptResource.axd”, “/_layouts/15/blank.js”, “/ScriptResource.axd”, “/WebResource.axd”, “/_layouts/15/1033/styles/corev15.css”, “/_layouts/15/1033/styles/error.css”, “/_layouts/15/images/favicon.ico”, “/_layouts/15/1033/strings.js”, “/_layouts/15/core.js”, and it can contain additional paths added by the administrator.

    While testing the CVE-2025-49706 bypass with the July 8, 2025 updates installed on our SharePoint debugging stand, we noticed some strange behavior. Not only did the bypass of CVE-2025-49706 work, but the entire exploit chain did! But wait! Didn’t the attackers use an additional Microsoft SharePoint Remote Code Execution Vulnerability CVE-2025-49704, which was supposed to be fixed in the same update? To understand why the entire exploit chain worked in our case, let’s take a look at the vulnerability CVE-2025-49704 and how it was fixed.

    CVE-2025-49704

    CVE-2025-49704 is an untrusted data deserialization vulnerability that exists due to improper validation of XML content. Looking at the exploit POST request, we can see that it contains two URL encoded parameters: “MSOtlPn_Uri” and “MSOtlPn_DWP”. We can see how they are handled by examining the code of the method GetPartPreviewAndPropertiesFromMarkup in Microsoft.SharePoint.dll. A quick analysis reveals that “MSOtlPn_Uri”  is a page URL that might be pointing to an any file in the CONTROLTEMPLATES folder and the parameter “MSOtlPn_DWP” contains something known as WebPart markup. This markup contains special directives that can be used to execute safe controls on a server and has a format very similar to XML.

    WebPart markup used by the attackers

    While this “XML” included in the “MSOtlPn_DWP” parameter does not itself contain a vulnerability, it allows attackers to instantiate the ExcelDataSet control from Microsoft.PerformancePoint.Scorecards.Client.dll with CompressedDataTable property set to malicious payload and trigger its processing using DataTable property getter.

    Code of the method that handles the contents of ExcelDataSet’s CompressedDataTable property in the DataTable property getter

    Looking at the code of the ExcelDataSet’s DataTable property getter in Microsoft.PerformancePoint.Scorecards.Client.dll, we find the method GetObjectFromCompressedBase64String, responsible for deserialization of CompressedDataTable property contents. The data provided as Base64 string is decoded, unzipped, and passed to the BinarySerialization.Deserialize method from Microsoft.SharePoint.dll.

    DataSet with XML content exploiting CVE-2025-49704 (deserialized)

    Attackers use this method to provide a malicious DataSet whose deserialized content is shown in the image above. It contains an XML with an element of dangerous type “System.Collections.Generic.List1[[System.Data.Services.Internal.ExpandedWrapper2[…], System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]]”, which allows attackers to execute arbitrary methods with the help of the well-known ExpandedWrapper technique aimed at exploitation of unsafe XML deserialization in applications based on the .NET framework. In fact, this shouldn’t be possible, since BinarySerialization.Deserialize in Microsoft.SharePoint.dll uses a special XmlValidator designed to protect against this technique by checking the types of all elements present in the provided XML and ensuring that they are on the list of allowed types. However, the exploit bypasses this check by placing the ExpandedWrapper object into the list.

    Now, to find out why the exploit worked on our SharePoint debugging stand with the July 8, 2025 updates installed, let’s take a look at how this vulnerability was fixed. In this patch, Microsoft did not really fix the vulnerability but only mitigated it by adding the new AddExcelDataSetToSafeControls class to the Microsoft.SharePoint.Upgrade namespace. This class contains new code that modifies the web.config file and marks the Microsoft.PerformancePoint.Scorecards.ExcelDataSet control as unsafe. Because SharePoint does not execute this code on its own after installing updates, the only way to achieve the security effect was to manually run a configuration upgrade using the SharePoint Products Configuration Wizard tool. Notably, the security guidance for CVE-2025-49704 does not mention the need for this step, which means at least some SharePoint administrators may skip it. Meanwhile, anyone who installed this update but did not manually perform a configuration upgrade remained vulnerable.

    CVE-2025-53770

    On July 20, 2025, Microsoft released an update with a proper fix for the CVE-2025-49704 vulnerability. This patch introduces an updated XmlValidator that now properly validates element types in XML, preventing exploitation of this vulnerability without requiring a configuration upgrade and, more importantly, addressing the root cause and preventing exploitation of the same vulnerability through controls other than Microsoft.PerformancePoint.Scorecards.ExcelDataSet.

    DataSet with XML content exploiting CVE-2025-49704 (deserialized)

    CVE-2020-1147

    Readers familiar with previous SharePoint exploits might feel that the vulnerability CVE-2025-49704/CVE-2025-53770 and the exploit used by the attackers looks very familiar and very similar to the older .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability CVE-2020-1147. In fact, if we compare the exploit for CVE-2020-1147 and an exploit for CVE-2025-49704/CVE-2025-53770, we can see that they are almost identical. The only difference is that in the exploit for CVE-2025-49704/CVE-2025-53770, the dangerous ExpandedWrapper object is placed in the list. This makes CVE-2025-53770 an updated fix for CVE-2020-1147.

    DataSet with XML content exploiting CVE-2020-1147

    Conclusions

    Despite the fact that patches for the ToolShell vulnerabilities are now available for deployment, we assess that this chain of exploits will continue being used by attackers for a long time. We have been observing the same situation with other notorious vulnerabilities, such as ProxyLogon, PrintNightmare, or EternalBlue. While they have been known for years, many threat actors still continue leveraging them in their attacks to compromise unpatched systems. We expect the ToolShell vulnerabilities to follow the same fate, as they can be exploited with extremely low effort and allow full control over the vulnerable server.

    To stay better protected against threats like ToolShell, we as a community should learn lessons from previous events in the industry related to critical vulnerabilities. Specifically, the speed of applying security patches nowadays is the most important factor when it comes to fighting such vulnerabilities. Since public exploits for these dangerous vulnerabilities appear very soon after vulnerability announcements, it is paramount to install patches as soon as possible, as a gap of even a few hours can make a critical difference.

    At the same time, it is important to protect enterprise networks against zero-day exploits, which can be leveraged when there is no available public patch for vulnerabilities. In this regard, it is critical to equip machines with reliable cybersecurity solutions that have proven effective in combatting ToolShell attacks before they were publicly disclosed.

    Kaspersky Next with its Behaviour detection component proactively protects against  exploitation of these vulnerabilities. Additionally, it is able to detect exploitation and the subsequent malicious activity.

    Kaspersky products detect the exploits and malware used in these attacks with the following verdicts:

    • UDS:DangerousObject.Multi.Generic
    • PDM:Exploit.Win32.Generic
    • PDM:Trojan.Win32.Generic
    • HEUR:Trojan.MSIL.Agent.gen
    • ASP.Agent.*
    • PowerShell.Agent.*

    MIL OSI Economics

  • MIL-OSI Economics: ToolShell: a story of five vulnerabilities in Microsoft SharePoint

    Source: Securelist – Kaspersky

    Headline: ToolShell: a story of five vulnerabilities in Microsoft SharePoint

    On July 19–20, 2025, various security companies and national CERTs published alerts about active exploitation of on-premise SharePoint servers. According to the reports, observed attacks did not require authentication, allowed attackers to gain full control over the infected servers, and were performed using an exploit chain of two vulnerabilities: CVE-2025-49704 and CVE-2025-49706, publicly named “ToolShell”. Additionally, on the same dates, Microsoft released out-of-band security patches for the vulnerabilities CVE-2025-53770 and CVE-2025-53771, aimed at addressing the security bypasses of previously issued fixes for CVE-2025-49704 and CVE-2025-49706. The release of the new, “proper” updates has caused confusion about exactly which vulnerabilities attackers are exploiting and whether they are using zero-day exploits.

    Kaspersky products proactively detected and blocked malicious activity linked to these attacks, which allowed us to gather statistics about the timeframe and spread of this campaign. Our statistics show that widespread exploitation started on July 18, 2025, and attackers targeted servers across the world in Egypt, Jordan, Russia, Vietnam, and Zambia. Entities across multiple sectors were affected: government, finance, manufacturing, forestry, and agriculture.

    While analyzing all artifacts related to these attacks, which were detected by our products and public information provided by external researchers, we found a dump of a POST request that was claimed to contain the malicious payload used in these attacks. After performing our own analysis, we were able to confirm that this dump indeed contained the malicious payload detected by our technologies, and that sending this single request to an affected SharePoint installation was enough to execute the malicious payload there.

    Our analysis of the exploit showed that it did rely on vulnerabilities fixed under CVE-2025-49704 and CVE-2025-49706, but by changing just one byte in the request, we were able to bypass those fixes.

    In this post, we provide detailed information about CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771, and one related vulnerability. Since the exploit code is already published online, is very easy to use, and poses a significant risk, we encourage all organizations to install the necessary updates.

    The exploit

    Our research started with an analysis of a POST request dump associated with this wave of attacks on SharePoint servers.

    Snippet of the exploit POST request

    We can see that this POST request targets the “/_layouts/15/ToolPane.aspx” endpoint and embeds two parameters: “MSOtlPn_Uri” and “MSOtlPn_DWP”. Looking at the code of ToolPane.aspx, we can see that this file itself does not contain much functionality and most of its code is located in the ToolPane class of the Microsoft.SharePoint.WebPartPages namespace in Microsoft.SharePoint.dll. Looking at this class reveals the code that works with the two parameters present in the exploit. However, accessing this endpoint under normal conditions is not possible without bypassing authentication on the attacked SharePoint server. This is where the first Microsoft SharePoint Server Spoofing Vulnerability CVE-2025-49706 comes into play.

    CVE-2025-49706

    This vulnerability is present in the method PostAuthenticateRequestHandler, in Microsoft.SharePoint.dll. SharePoint requires Internet Information Services (IIS) to be configured in integrated mode. In this mode, the IIS and ASP.NET authentication stages are unified. As a result, the outcome of IIS authentication is not determined until the PostAuthenticateRequest stage, at which point both the ASP.NET and IIS authentication methods have been completed. Therefore, the PostAuthenticateRequestHandler method utilizes a series of flags to track potential authentication violations. A logic bug in this method enables an authentication bypass if the “Referrer” header of the HTTP request is equal to “/_layouts/SignOut.aspx”, “/_layouts/14/SignOut.aspx”, or “/_layouts/15/SignOut.aspx” using case insensitive comparison.

    Vulnerable code in PostAuthenticateRequestHandler method (Microsoft.SharePoint.dll version 16.0.10417.20018)

    The code displayed in the image above handles the sign-out request and is also triggered when the sign-out page is specified as the referrer. When flag6 is set to false and flag7 is set to true, both conditional branches that could potentially throw an “Unauthorized Access” exception are bypassed.

    Unauthorized access checks bypassed by the exploit

    On July 8, 2025, Microsoft released an update that addressed this vulnerability by introducing additional checks to detect the usage of the “ToolPane.aspx” endpoint with the sign-out page specified as the referrer.

    CVE-2025-49706 fix (Microsoft.SharePoint.dll version 16.0.10417.20027)

    The added check uses case insensitive comparison to verify if the requested path ends with “ToolPane.aspx”. Is it possible to bypass this check, say, by using a different endpoint? Our testing has shown that this check can be easily bypassed.

    CVE-2025-53771

    We were able to successfully bypass the patch for vulnerability CVE-2025-49706 by adding just one byte to the exploit POST request. All that was required to bypass this patch was to add a “/” (slash) to the end of the requested “ToolPane.aspx” path.

    Bypass for CVE-2025-49706 fix

    On July 20, 2025, Microsoft released an update that fixed this bypass as CVE-2025-53771. This fix replaces the “ToolPane.aspx” check to instead check whether the requested path is in the list of paths allowed for use with the sign-out page specified as the referrer.

    CVE-2025-53771 fix (Microsoft.SharePoint.dll version 16.0.10417.20037)

    This allowlist includes the following paths: “/_layouts/15/SignOut.aspx”, “/_layouts/15/1033/initstrings.js”, “/_layouts/15/init.js”, “/_layouts/15/theming.js”, “/ScriptResource.axd”, “/_layouts/15/blank.js”, “/ScriptResource.axd”, “/WebResource.axd”, “/_layouts/15/1033/styles/corev15.css”, “/_layouts/15/1033/styles/error.css”, “/_layouts/15/images/favicon.ico”, “/_layouts/15/1033/strings.js”, “/_layouts/15/core.js”, and it can contain additional paths added by the administrator.

    While testing the CVE-2025-49706 bypass with the July 8, 2025 updates installed on our SharePoint debugging stand, we noticed some strange behavior. Not only did the bypass of CVE-2025-49706 work, but the entire exploit chain did! But wait! Didn’t the attackers use an additional Microsoft SharePoint Remote Code Execution Vulnerability CVE-2025-49704, which was supposed to be fixed in the same update? To understand why the entire exploit chain worked in our case, let’s take a look at the vulnerability CVE-2025-49704 and how it was fixed.

    CVE-2025-49704

    CVE-2025-49704 is an untrusted data deserialization vulnerability that exists due to improper validation of XML content. Looking at the exploit POST request, we can see that it contains two URL encoded parameters: “MSOtlPn_Uri” and “MSOtlPn_DWP”. We can see how they are handled by examining the code of the method GetPartPreviewAndPropertiesFromMarkup in Microsoft.SharePoint.dll. A quick analysis reveals that “MSOtlPn_Uri”  is a page URL that might be pointing to an any file in the CONTROLTEMPLATES folder and the parameter “MSOtlPn_DWP” contains something known as WebPart markup. This markup contains special directives that can be used to execute safe controls on a server and has a format very similar to XML.

    WebPart markup used by the attackers

    While this “XML” included in the “MSOtlPn_DWP” parameter does not itself contain a vulnerability, it allows attackers to instantiate the ExcelDataSet control from Microsoft.PerformancePoint.Scorecards.Client.dll with CompressedDataTable property set to malicious payload and trigger its processing using DataTable property getter.

    Code of the method that handles the contents of ExcelDataSet’s CompressedDataTable property in the DataTable property getter

    Looking at the code of the ExcelDataSet’s DataTable property getter in Microsoft.PerformancePoint.Scorecards.Client.dll, we find the method GetObjectFromCompressedBase64String, responsible for deserialization of CompressedDataTable property contents. The data provided as Base64 string is decoded, unzipped, and passed to the BinarySerialization.Deserialize method from Microsoft.SharePoint.dll.

    DataSet with XML content exploiting CVE-2025-49704 (deserialized)

    Attackers use this method to provide a malicious DataSet whose deserialized content is shown in the image above. It contains an XML with an element of dangerous type “System.Collections.Generic.List1[[System.Data.Services.Internal.ExpandedWrapper2[…], System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089]]”, which allows attackers to execute arbitrary methods with the help of the well-known ExpandedWrapper technique aimed at exploitation of unsafe XML deserialization in applications based on the .NET framework. In fact, this shouldn’t be possible, since BinarySerialization.Deserialize in Microsoft.SharePoint.dll uses a special XmlValidator designed to protect against this technique by checking the types of all elements present in the provided XML and ensuring that they are on the list of allowed types. However, the exploit bypasses this check by placing the ExpandedWrapper object into the list.

    Now, to find out why the exploit worked on our SharePoint debugging stand with the July 8, 2025 updates installed, let’s take a look at how this vulnerability was fixed. In this patch, Microsoft did not really fix the vulnerability but only mitigated it by adding the new AddExcelDataSetToSafeControls class to the Microsoft.SharePoint.Upgrade namespace. This class contains new code that modifies the web.config file and marks the Microsoft.PerformancePoint.Scorecards.ExcelDataSet control as unsafe. Because SharePoint does not execute this code on its own after installing updates, the only way to achieve the security effect was to manually run a configuration upgrade using the SharePoint Products Configuration Wizard tool. Notably, the security guidance for CVE-2025-49704 does not mention the need for this step, which means at least some SharePoint administrators may skip it. Meanwhile, anyone who installed this update but did not manually perform a configuration upgrade remained vulnerable.

    CVE-2025-53770

    On July 20, 2025, Microsoft released an update with a proper fix for the CVE-2025-49704 vulnerability. This patch introduces an updated XmlValidator that now properly validates element types in XML, preventing exploitation of this vulnerability without requiring a configuration upgrade and, more importantly, addressing the root cause and preventing exploitation of the same vulnerability through controls other than Microsoft.PerformancePoint.Scorecards.ExcelDataSet.

    DataSet with XML content exploiting CVE-2025-49704 (deserialized)

    CVE-2020-1147

    Readers familiar with previous SharePoint exploits might feel that the vulnerability CVE-2025-49704/CVE-2025-53770 and the exploit used by the attackers looks very familiar and very similar to the older .NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability CVE-2020-1147. In fact, if we compare the exploit for CVE-2020-1147 and an exploit for CVE-2025-49704/CVE-2025-53770, we can see that they are almost identical. The only difference is that in the exploit for CVE-2025-49704/CVE-2025-53770, the dangerous ExpandedWrapper object is placed in the list. This makes CVE-2025-53770 an updated fix for CVE-2020-1147.

    DataSet with XML content exploiting CVE-2020-1147

    Conclusions

    Despite the fact that patches for the ToolShell vulnerabilities are now available for deployment, we assess that this chain of exploits will continue being used by attackers for a long time. We have been observing the same situation with other notorious vulnerabilities, such as ProxyLogon, PrintNightmare, or EternalBlue. While they have been known for years, many threat actors still continue leveraging them in their attacks to compromise unpatched systems. We expect the ToolShell vulnerabilities to follow the same fate, as they can be exploited with extremely low effort and allow full control over the vulnerable server.

    To stay better protected against threats like ToolShell, we as a community should learn lessons from previous events in the industry related to critical vulnerabilities. Specifically, the speed of applying security patches nowadays is the most important factor when it comes to fighting such vulnerabilities. Since public exploits for these dangerous vulnerabilities appear very soon after vulnerability announcements, it is paramount to install patches as soon as possible, as a gap of even a few hours can make a critical difference.

    At the same time, it is important to protect enterprise networks against zero-day exploits, which can be leveraged when there is no available public patch for vulnerabilities. In this regard, it is critical to equip machines with reliable cybersecurity solutions that have proven effective in combatting ToolShell attacks before they were publicly disclosed.

    Kaspersky Next with its Behaviour detection component proactively protects against  exploitation of these vulnerabilities. Additionally, it is able to detect exploitation and the subsequent malicious activity.

    Kaspersky products detect the exploits and malware used in these attacks with the following verdicts:

    • UDS:DangerousObject.Multi.Generic
    • PDM:Exploit.Win32.Generic
    • PDM:Trojan.Win32.Generic
    • HEUR:Trojan.MSIL.Agent.gen
    • ASP.Agent.*
    • PowerShell.Agent.*

    MIL OSI Economics