Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in.
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
About this summary. This is a short, independently written summary of an article first published by Security Affairs. Cyber Security News did not report or verify the underlying story. Read the original: https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html

Source attribution: headline and facts are from Security Affairs (securityaffairs.com). Summary method: excerpt of the source description. See our source attribution policy.






