LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
ransomwarecritical

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The…

ZeroDay News ·

Source: The Hacker News

Photo: U.S. Air National Guard photo by Staff Sgt. Adam Welch (Public domain) via Wikimedia Commons

The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The attacks have primarily targeted organizations in Portuguese- and Spanish-speaking countries.

The technical mechanism behind disabling security tools often involves exploiting system-level privileges gained through the initial SharePoint compromise. Once an attacker establishes a foothold, they can leverage elevated permissions to interfere with endpoint detection and response (EDR) agents, antivirus software, and other security monitoring tools. This typically involves terminating security processes, deleting security-related files, or modifying system configurations to prevent security software from functioning correctly. Such actions are a common precursor to deploying more destructive payloads like ransomware, as they reduce the likelihood of detection and intervention.

The affected product is Microsoft SharePoint, a widely used web-based collaborative platform that integrates with Microsoft Office. SharePoint is commonly deployed across various organizational types for document management, internal communication, and workflow automation. Its extensive integration with enterprise systems and often internet-facing presence makes it a high-value target for threat actors seeking broad access to an organization's network.

The likely scope of these attacks appears to be geographically focused on Portuguese- and Spanish-speaking countries, with specific targeting of critical infrastructure, government, and education sectors. These sectors are frequently targeted due to the sensitive nature of their data, their operational importance, and sometimes their perceived lower cybersecurity maturity compared to other industries. The use of both old and new vulnerabilities suggests a persistent and adaptive threat actor capable of leveraging a range of exploits.

Mitigation guidance for this class of issue typically emphasizes a multi-layered approach. Organizations should prioritize keeping all software, especially internet-facing applications like SharePoint, fully patched and updated to address known vulnerabilities. Implementing strong access controls, including multi-factor authentication (MFA) for all administrative interfaces and critical systems, is crucial. Network segmentation can limit the lateral movement of attackers even if an initial compromise occurs. Regular security audits, penetration testing, and robust logging and monitoring are also essential to detect and respond to suspicious activity promptly.

This reported activity by Warlock underscores the persistent threat posed by state-sponsored or state-aligned actors who leverage known and unknown vulnerabilities in widely adopted enterprise software. The focus on disabling security tools before deploying ransomware highlights a sophisticated approach aimed at maximizing the impact and success of their operations. It serves as a reminder for organizations, particularly those in critical sectors, to maintain rigorous patch management, strong defensive postures, and proactive threat hunting capabilities to counter evolving cyber threats.

ransomwarevulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

AI agents have been observed attempting SQL injection attacks while searching government data, with investigators successfully tracing an AI agent's path from a research task to reconnaissance activities. This comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Zammad…

nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

President Trump has reportedly named National Intelligence Director Jay Clayton to lead a newly established federal task force focused on artificial intelligence. This development follows a recent gathering at the White House where the President met with leading executives from various AI companies.