CRITICALRansomware
Global

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

·Source: The Hacker News

Updated:

Executive Summary

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the

Analysis

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Source Attribution

Originally published by The Hacker News on Oct 3, 2026.

Related Threats

HIGHRansomware

Japan hands over ‘Qilin’ hacker group member to Germany

JiJi reports: Japanese police have captured a Russian national believed to be a key member of the “Qilin” international hacker group and extradited him to Germany, investigative sources said Tuesday. Qilin is believed to have carried out ransomware attacks against companies worldwide, causing major damage through data encryption. In 2025, the group claimed responsibility online... Source

DataBreaches.net
LOWMalware

New Linux malware turns vulnerable IoT devices into proxy nodes

A new Linux backdoor is turning vulnerable internet-facing devices into remotely controlled proxy nodes, while using the public Session Traversal Utilities for NAT (STUN) infrastructure to blend into normal VoIP and WebRTC traffic. Fortinet’s FortiGuard Labs said it has been tracking the malware, dubbed ClingSTUN, across multiple attacks exploiting known vulnerabilities in routers, IoT devices, DV

CSO Online
CRITICALZero Day

The AI app builder your team trusts has a root-level backdoor

The fastest-growing category of enterprise software right now is also the least scrutinized from a security standpoint. AI application platforms — tools that let teams build, connect and automate AI-powered workflows without writing much code — are landing in production environments faster than security teams can assess them. They connect to your APIs, your databases, your cloud credentials and yo

CVE-2026-0768CVE-2026-0769
CSO Online