Warlock continues exploiting SharePoint flaws in ransomware attacks

First reported by The Hacker News at · Updated · 2 sources

The attacks have affected critical infrastructure, government and education organizations. According to The Hacker News, researchers observed activity targeting organizations in Portuguese- and Spanish-speaking countries. Security Affairs reports that the group continues to exploit unpatched vulnerabilities more than a year after gaining attention for attacks using the SharePoint flaw chain called ToolShell.

  • The Hacker News reports that Warlock disables security tools.

Covered by 2 publishers within 17 hours of the first report.

Reporting2

The Hacker News Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware · info@thehackernews.com (The Hacker News)