Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware Ravie LakshmananOct 03, 2026Vulnerability / Critical Infrastructure The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the past two months, Longlegs has attacked at least four organizations, including two critical infrastructure operators (a water utility and a telecommunications provider), a regional government body, and a university," the Broadcom-owned cybersecurity unit said. "Victims were in Portuguese- and Spanish-speaking countries, spanning Europe, Africa, and Latin America." Warlock, also tracked…
CVEs: CVE-2025-1055
Original source: thehackernews.com