Warlock Ransomware: Deployed by Storm-2603 in SharePoint Attacks
Ransomware deployed by threat actor Storm-2603, often exploiting known vulnerabilities in on-premises SharePoint servers. Used in parallel with other techniques to establish…
Ransomware deployed by threat actor Storm-2603, often exploiting known vulnerabilities in on-premises SharePoint servers. Used in parallel with other techniques to establish…
watchTowr reported active exploitation of CVE-2026-50522 against on-premises SharePoint deployments, with attackers stealing machine keys via a single request.
ACR Stealer targets SharePoint folders for document exfiltration.
Defused Cyber disclosed that threat actors are exploiting CVE-2026-50522 to deliver .NET deserialization payloads to SharePoint sign-in endpoints without authentication.