Security News

Warlock Ransomware Hits Critical Infrastructure via Unpatched SharePoint Servers

The Record · 3 Oct 2026
Key Takeaway Businesses running Microsoft SharePoint should urgently apply all available security patches and review access logs for unusual activity, as unpatched servers remain an active target for ransomware groups.

Security researchers at Symantec have identified an ongoing ransomware campaign targeting critical infrastructure organisations in Europe, Africa and Latin America, including a water utility, a telecommunications provider, a university and a regional government. The attackers, believed to be a Chinese group, are using a ransomware strain called Warlock and exploiting several Microsoft SharePoint vulnerabilities to gain access.

Microsoft first flagged Warlock attacks last year linked to the 'ToolShell' SharePoint flaws, but Symantec's report shows the campaign has continued into 2026, now also exploiting newer SharePoint vulnerabilities recently highlighted by US authorities. In one case, attackers used a tool to disable security software across dozens of systems before deploying the ransomware, following extensive reconnaissance designed to make their activity look like normal admin or developer traffic.

The findings follow a recent US Cybersecurity and Infrastructure Security Agency warning about six new SharePoint vulnerabilities giving attackers broad access to affected organisations. Because SharePoint often stores sensitive documents and is tightly linked to Microsoft's authentication systems, a single unpatched server can give attackers a path deep into a victim's wider network.

Primary source cisa.gov ->

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.