Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

First reported by BleepingComputer at · Updated · 3 sources

Warlock has targeted a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities to gain initial access. The suspected China-linked group continues to exploit unpatched flaws, with organizations in Portuguese- and Spanish-speaking countries among its targets, according to The Hacker News.

  • Security Affairs says Warlock exploited the ToolShell zero-day chain in mid-2025.

Covered by 3 publishers within 37 hours of the first report.

Reporting3

The Hacker News Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware · info@thehackernews.com (The Hacker News)

Related

Topics RansomwareZero-day vulnerabilities