Warlock continues exploiting SharePoint flaws in ransomware attacks
The attacks have affected critical infrastructure, government and education organizations. According to The Hacker News, researchers observed activity targeting organizations in Portuguese- and Spanish-speaking countries. Security Affairs reports that the group continues to exploit unpatched vulnerabilities more than a year after gaining attention for attacks using the SharePoint flaw chain called ToolShell.
- The Hacker News reports that Warlock disables security tools.
Covered by 2 publishers within 17 hours of the first report.
Reporting2
The Hacker News Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware · info@thehackernews.com (The Hacker News)
Security Affairs Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure · Pierluigi Paganini