Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Cybersecurity · October 4, 2026

Cybersecurity·thehackernews.com

Security researchers at Symantec and Carbon Black report that the suspected China-linked group Warlock is still abusing older and newer Microsoft SharePoint vulnerabilities to break into networks. The campaign has struck critical infrastructure, government, and education organizations in Portuguese- and Spanish-speaking countries, shutting off defensive tools before dropping ransomware.

// source: thehackernews.com ↗

← Back to Blog