LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
ransomwarehigh

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water…

ZeroDay News ·

Source: Security Affairs

The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water utilities and telecommunications providers, alongside government entities and universities across multiple continents.

The vulnerabilities, collectively referred to as ToolShell, first gained attention in mid-2025. Despite their age, they remain an effective entry point for the attackers. Longlegs typically establishes initial access by placing a webshell in the SharePoint LAYOUTS directory, designed to function across various SharePoint versions. Following this, the attackers steal the server's ASP.NET machine keys to craft a signed payload, enabling arbitrary code execution within the SharePoint application. This method relies on the presence of unpatched SharePoint servers.

In the past two months alone, Longlegs has compromised at least four organizations: a water utility, a telecom provider, a regional government body, and a university. These recent targets are located in Portuguese or Spanish-speaking countries across Europe, Africa, and Latin America. However, the group's targeting is not geographically restricted, with previous attacks observed in the US, Brazil, India, Russia, Taiwan, and Japan. The recent focus on specific language regions may indicate either a search for any exposed and unpatched SharePoint servers or a deliberate targeting strategy.

Once inside a network, the attackers employ DLL sideloading to execute additional payloads. These files are often downloaded from legitimate hosting services such as catbox.moe and wasabisys.com, which helps obscure the malicious traffic. Before deploying the ransomware, Longlegs utilizes a signed but vulnerable driver, K7RKScan, to disable security software, a technique known as "bring your own vulnerable driver." The group has also been observed installing Visual Studio Code's tunneling feature as a service, providing covert remote access that can mimic normal developer activity.

Symantec detailed a specific attack against a critical infrastructure operator that commenced on July 22, 2026, with the deployment of a webshell on a SharePoint server. Within two days, the attackers performed reconnaissance, removed staging files, and introduced DLL sideloading tools. By July 28, they initiated exploitation using a deserialization gadget to achieve code execution within SharePoint via a forged, signed payload. The attackers then retrieved three distinct installer packages from two different hosting services within 90 minutes, suggesting preparedness with multiple delivery options.

The intrusion rapidly expanded from the initial two SharePoint servers to the broader domain. On July 28 and 29, the attackers repeatedly added a domain account named SPSEPRDSetup to the local Administrators group on three additional hosts, leveraging a name that could blend in with legitimate SharePoint-related accounts. By July 31, a tool designed to disable antivirus and EDR solutions was deployed across the network. In one instance, this tool was pushed to at least 40 hosts within approximately two hours.

Immediately following the disabling of security software, Warlock ransomware was deployed. The attackers utilized the domain's SYSVOL share to distribute the ransomware, taking advantage of its automatic replication across domain controllers. Symantec observed the malicious files being delivered via normal domain replication traffic, specifically through the dfsrs.exe Windows service. The rapid progression from disabling protection to encrypting systems highlights the speed and efficiency of the attacks.

The continued success of Warlock ransomware underscores the ongoing risk posed by unpatched SharePoint vulnerabilities. Organizations running on-premises SharePoint installations are strongly advised to ensure all relevant patches and mitigations are applied to prevent exploitation by groups like Longlegs.

ransomwaresharepointvulnerabilitycritical infrastructurelonglegs
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

CVE-2026-88779high

NetScaler CVE-2026-88779 Exploited Before Publication

NetScaler's CVE-2026-88779 was exploited before its official publication date, leaving no patch window. The European Union's EUVD catalogue lists it as exploited.

artificial intelligence

SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2

AI agents have been observed attempting SQL injection attacks while searching government data, with investigators successfully tracing an AI agent's path from a research task to reconnaissance activities. This comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Zammad…

nation-state

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

President Trump has reportedly named National Intelligence Director Jay Clayton to lead a newly established federal task force focused on artificial intelligence. This development follows a recent gathering at the White House where the President met with leading executives from various AI companies.