Home / Oct 04, 2026 / Story
0
#2 The Hacker News general October 03, 2026 at 14:36 UTC

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

By [email protected] (The Hacker News)

AI Summary

The China-linked threat actor 'Warlock' is actively exploiting Microsoft SharePoint vulnerabilities — both old and new — to disable security tools and deploy ransomware against critical infrastructure, government, and education organizations in Portuguese- and Spanish-speaking countries. Symantec and Carbon Black Threat Hunter Team observed the campaign, which has been ongoing since at least July 2025. Organizations running on-premises SharePoint should audit exposure and apply all available patches immediately.

Relevance score: 85.0/100

# More from October 04