Skip to content
Warlock continues SharePoint exploits, ShinyHunters member flips

Warlock continues SharePoint exploits, ShinyHunters member flips

Cisoseries • October 5, 2026

Following up on a story we covered in July of 2025, the ransomware named Warlock “continues to exploit unpatched SharePoint ToolShell flaws to breach water utilities, telecoms, governments, and universities worldwide.” Symantec group says the China-based gang behind Warlock has been recently hitting utilities in Portuguese and Spanish speaking countries, but its actions show it is not focused on one specific region, but may be simply looking for exposed and unpatched SharePoint servers, or working from a specific target list.

ShinyHunters member detained in Jordan

A person who is suspected of being a member of the ShinyHunters digital extortion group, and who goes by the online alias “Rey,” has allegedly been detained by authorities in Jordan, according to Reuters. The individual whose real name is Saif ‌al-Din Khader, is apparently cooperating with the FBI to identify other members of the group. Brian Krebs had labeled Rey as “one of the three administrators of Scattered LAPSUS$ Hunters (SLH or SLSH), amalgamated group.

China-aligned espionage group targets American AI policy experts

The group, labeled TA419, has been allegedly using credential phishing campaigns to target AI experts “working for U.S. think tanks, universities, and legal sector organizations.” In a technique we have seen before, their campaigns “impersonate prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026. The phishing email carried the subject line “Request for Feedback on Military Integration of Claude.” Proofpoint suggests that this activity supports espionage into AI policy rather than sabotage or theft. It uses a OneDrive adversary-in-the-middle (AitM) credential phishing page after completing a Cloudflare Turnstile check.

Mississippi town suffers cyberattack

Vicksburg, Mississippi located on the state’s western border is investigating a ransomware attack that has affected payments for utilities but has not impacted emergency services. Mayor Willis Thompson said that “no one’s services will be shut off while the investigation is ongoing and no penalties will be issued for late payments.” During this restoration period, no information has been released any data stolen or the identify of the group behind the attack.

Huge thanks to our sponsor, Vanta

Danish university suffers data breach

The Technical University of Denmark (DTU) says “information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data.” Officials state that the attacker used compromised credentials to log into the university’s identity and access management (IAM) system, allowing access to more than two decades of user data, although at this point they cannot “determine precisely what information was downloaded or how many people have been affected.” It is known however that this database stores information for nearly 40,000 active users and around 160,000 former users, including PII, addresses, job titles, and even data on of kin.

Frontline Education breach exposes school district employee data

Frontline Education is “an edtech company that provides administration and workforce management software and services used by school districts.” It is now notifying school districts of a data breach resulting from exploitation of a vulnerability in third-party software that “allowed unauthorized access to a portion of the environment.” Data stolen includes employee information, including Social Security numbers. “The company has not disclosed which third-party application was involved or when the unauthorized access first occurred.”

California slaps OpenAI’s wandering AI agents with a subpoena

Fortra patches critical vulnerabilities in BoKS

Fortra has “released patches for eight vulnerabilities in Core Privileged Access Manager (BoKS), including three critical-severity bugs.” BoKS provides “central management of Unix and Linux fleets, enabling policy enforcement and access control across accounts.” Its name, by the way, comes from the acronym of its original software developed in Sweden 30 years ago. The three most severe of the vulnerabilities have CVSS scores of 9.9, 9.8 and 9.1. Additional details on these vulnerabilities (CVE-2026-79901, CVE-2026-7989, and CVE-2026-12627) are available in the show notes to this episode.

Extracted Entities