Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Warlock has targeted a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities to gain initial access. The suspected China-linked group continues to exploit unpatched flaws, with organizations in Portuguese- and Spanish-speaking countries among its targets, according to The Hacker News.
- Security Affairs says Warlock exploited the ToolShell zero-day chain in mid-2025.
Covered by 3 publishers within 37 hours of the first report.
Reporting3
BleepingComputer Warlock ransomware breach SharePoint in water, telecom operator attacks · Ionut Ilascu
The Hacker News Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware · info@thehackernews.com (The Hacker News)
Security Affairs Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure · Pierluigi Paganini