Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Warlock ransomware continues to breach water utilities, telecoms, governments, and universities worldwide through unpatched SharePoint flaws. The group made headlines in mid-2025 exploiting the ToolShell SharePoint zero-day chain, and more than a year later is still using the same entry point successfully. The activity shows that long-unpatched servers remain easy targets for ransomware operators.

Source: securityaffairs.com

Curated Permalink