#2
The Hacker News
general
October 03, 2026 at 14:36 UTC
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
By [email protected] (The Hacker News)
AI Summary
The China-linked threat actor 'Warlock' is actively exploiting Microsoft SharePoint vulnerabilities — both old and new — to disable security tools and deploy ransomware against critical infrastructure, government, and education organizations in Portuguese- and Spanish-speaking countries. Symantec and Carbon Black Threat Hunter Team observed the campaign, which has been ongoing since at least July 2025. Organizations running on-premises SharePoint should audit exposure and apply all available patches immediately.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →