Back to all news
Security

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News·October 3, 2026·1 min read
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor Warlock continues to exploit Microsoft SharePoint vulnerabilities, both old and new, to disable security tools and deploy ransomware. Attacks target organizations in Portuguese- and Spanish-speaking countries, including critical infrastructure, government, and education sectors. The activity was observed by Symantec and Carbon Black Threat Hunter Team, highlighting ongoing risks from SharePoint flaws.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store