Vulnerabilities & Exploits · Ransomware
Warlock Keeps SharePoint as a Ransomware Doorway Symantec says Warlock, the China-nexus group also tracked as Longlegs and Storm-2603, kept abusing Microsoft SharePoint Server in the past two months, hitting at least four organizations in Portuguese- and Spanish-speaking countries. The victims included a water utility, a telecom provider, a regional government body, and a university.
The group’s playbook starts with SharePoint bugs, including the 2025 ToolShell flaws and newer CVEs, then moves into the Windows domain. Symantec says one intrusion used a tool to disable security software on at least 40 hosts, then staged Warlock in the domain’s SYSVOL share, which Windows replicates automatically, so the ransomware reached at least 33 systems without hand-copying it everywhere.
That makes the SharePoint server a launch point, not the end of the incident. If on-prem SharePoint sits inside the same domain as file shares and workstations, a single internet-facing foothold can turn into domain-wide ransomware spread and security-tool disablement.
3 sources · 4h ago
CVEs in this update
10 CVEs
Across Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition.
4 critical · 2 high · 4 medium · 0 low
9 in CISA KEV · 5 with EPSS above 1%
4 with functional or packaged public exploit code
Highest severity: CVE-2025-53770 · 9.8 CRITICAL
Highest EPSS: CVE-2025-53770 · 100%
Timeline Oct 2 Reported by Industrial Cyber Oct 1 Reported by Dark Reading Aug 21 CISA federal deadline for CVE-2026-55040 passedAug 18 CVE-2026-55040 added to CISA KEVJul 25 CISA federal deadline for CVE-2026-50522 passedJul 22 CVE-2026-50522 added to CISA KEVJul 19 CISA federal deadline for CVE-2026-58644 passedJul 17 CISA federal deadline for CVE-2026-56164 passedJul 16 CVE-2026-58644 added to CISA KEVJul 14 CVE-2026-56164 added to CISA KEVJul 4 CISA federal deadline for CVE-2026-45659 passedJul 1 CVE-2026-45659 added to CISA KEVApr 28 CISA federal deadline for CVE-2026-32201 passedApr 14 CVE-2026-32201 added to CISA KEVJul 23 CISA federal deadline for CVE-2025-49704 passedJul 22 CVE-2025-49704 added to CISA KEVJul 21 CISA federal deadline for CVE-2025-53770 passedJul 20 CVE-2025-53770 added to CISA KEVSources Oct 2 Industrial Cyber
Symantec reports Warlock ransomware group targets water, telecom, government organizations through SharePoint flaws - Industrial Cyber
Symantec researchers report that Warlock ransomware group targets water, telecom and government organizations through SharePoint flaws.
original Oct 2 SecurityWeek
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.
original Oct 1 Dark Reading
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-10-02
Every edition of this story: Warlock Keeps SharePoint as a Ransomware Doorway
More from today
Vulnerabilities & Exploits · Ransomware
Warlock Keeps SharePoint as a Ransomware Doorway Symantec says Warlock, the China-nexus group also tracked as Longlegs and Storm-2603, kept abusing Microsoft SharePoint Server in the past two months, hitting at least four organizations in Portuguese- and Spanish-speaking countries. The victims included a water utility, a telecom provider, a regional government body, and a university.
The group’s playbook starts with SharePoint bugs, including the 2025 ToolShell flaws and newer CVEs, then moves into the Windows domain. Symantec says one intrusion used a tool to disable security software on at least 40 hosts, then staged Warlock in the domain’s SYSVOL share, which Windows replicates automatically, so the ransomware reached at least 33 systems without hand-copying it everywhere.
That makes the SharePoint server a launch point, not the end of the incident. If on-prem SharePoint sits inside the same domain as file shares and workstations, a single internet-facing foothold can turn into domain-wide ransomware spread and security-tool disablement.
3 sources · 4h ago
CVEs in this update
10 CVEs
Across Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition.
4 critical · 2 high · 4 medium · 0 low
9 in CISA KEV · 5 with EPSS above 1%
4 with functional or packaged public exploit code
Highest severity: CVE-2025-53770 · 9.8 CRITICAL
Highest EPSS: CVE-2025-53770 · 100%
Timeline Oct 2 Reported by Industrial Cyber Oct 1 Reported by Dark Reading Aug 21 CISA federal deadline for CVE-2026-55040 passedAug 18 CVE-2026-55040 added to CISA KEVJul 25 CISA federal deadline for CVE-2026-50522 passedJul 22 CVE-2026-50522 added to CISA KEVJul 19 CISA federal deadline for CVE-2026-58644 passedJul 17 CISA federal deadline for CVE-2026-56164 passedJul 16 CVE-2026-58644 added to CISA KEVJul 14 CVE-2026-56164 added to CISA KEVJul 4 CISA federal deadline for CVE-2026-45659 passedJul 1 CVE-2026-45659 added to CISA KEVApr 28 CISA federal deadline for CVE-2026-32201 passedApr 14 CVE-2026-32201 added to CISA KEVJul 23 CISA federal deadline for CVE-2025-49704 passedJul 22 CVE-2025-49704 added to CISA KEVJul 21 CISA federal deadline for CVE-2025-53770 passedJul 20 CVE-2025-53770 added to CISA KEVSources Oct 2 Industrial Cyber
Symantec reports Warlock ransomware group targets water, telecom, government organizations through SharePoint flaws - Industrial Cyber
Symantec researchers report that Warlock ransomware group targets water, telecom and government organizations through SharePoint flaws.
original Oct 2 SecurityWeek
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.
original Oct 1 Dark Reading
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-10-02
Every edition of this story: Warlock Keeps SharePoint as a Ransomware Doorway
More from today