Warlock ransomware targets water and telecom firms via SharePoint breach
Security firms Symantec and Carbon Black reported on October 1, 2026 that threat actors deployed Warlock ransomware against at least four organizations, including water and telecommunications operators. Attackers likely gained initial access by exploiting a vulnerability in Microsoft SharePoint Server before moving through the network. They placed the ransomware binary in the SYSVOL directory, using domain controller replication to distribute it across systems. The group executed tools to disable security software on at least 40 machines within two hours, leading to ransom notes appearing on 33 hosts. The specific vulnerabilities used in these recent intrusions have not been officially confirmed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in