⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

October 3, 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware Ravie LakshmananOct 03, 2026Vulnerability / Critical Infrastructure The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university," the Broadcom-owned cybersecurity unit said. "Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America." Warlock, also tracked…

CVEs: CVE-2025-1055