Skip to content

Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators

Cybersecuritynews •Guru Baran • October 1, 2026

A China-nexus threat actor is continuing to exploit Microsoft SharePoint Server vulnerabilities to deploy Warlock ransomware, with recent attacks striking essential-service and public-sector organizations across Portuguese- and Spanish-speaking countries. Symantec tracks the operator as Longlegs, while Microsoft uses Storm-2603; earlier activity has also been linked to CL-CRI-1040, CamoFei, and ChamelGang. During the past two months, […]

Extracted Entities

Attack Types (1)

Ransomware Groups (1)