> Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
[DATE: 03/10/2026 14:36]
[LANGUAGE: EN]
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries.
The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations.
"In the