← Back to feed
Breaches & RansomwareEmerging1 sourceOct 3, 2026 · 14:36via The Hacker News

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Brief

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.

The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations.

"In the

Read more on The Hacker News→