Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News - Oct 3, 2026

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

Read full article

More News