LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
ransomwarehigh

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.

ZeroDay News ·

Source: The Record

A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.

Victims identified in the ongoing attacks include a water utility, a telecommunications provider, a university, and a regional government, spanning locations across Europe, Africa, and Latin America. This activity extends a pattern of exploitation against SharePoint that Microsoft previously highlighted in 2025, when it warned of Chinese hackers using Warlock ransomware to target vulnerabilities colloquially known as "ToolShell."

The current campaign, observed continuing into 2026, also leverages newer SharePoint vulnerabilities recently flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This indicates that organizations have not consistently applied patches for either the 2025 or the more recent 2026 SharePoint security flaws.

The focus on Portuguese and Spanish-speaking nations could suggest either opportunistic targeting of exposed, vulnerable SharePoint servers or a more deliberate strategic objective. The inclusion of critical infrastructure operators among the compromised entities underscores the potential for significant real-world disruption from successful ransomware attacks against essential services.

In one observed incident, attackers utilized a specialized tool to disable security software across dozens of hosts before deploying the Warlock ransomware. The threat actors conducted extensive reconnaissance on compromised systems, installing various tools designed to camouflage their activities by mimicking normal traffic typically originating from developer or administrator workstations.

SharePoint remains a high-value target for both financially motivated and state-sponsored groups seeking intelligence, given its common use for storing confidential documents and its deep integration with Microsoft's authentication services. A successful foothold in SharePoint can enable attackers to penetrate deeper into victim networks.

Last year, a hacking campaign against SharePoint instances caused widespread concern after numerous prominent organizations were breached through these vulnerabilities. Reports indicated that at least 400 governments and businesses were allegedly compromised, including the National Nuclear Security Administration, the National Institutes of Health, and the Department of Homeland Security. Additionally, several Swiss government institutions were attacked via SharePoint vulnerabilities in August of last year.

Microsoft has not publicly linked the Chinese group behind Warlock to any other tracked state-backed Chinese groups, though it noted last year that the hackers initially used a strain of LockBit ransomware before transitioning to Warlock. Previous Warlock ransomware attacks have been documented against organizations in the U.S., Russia, Brazil, India, Taiwan, and Japan.

ransomwarecritical infrastructuresharepointvulnerabilitieschina
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.