HackerFeeds

CyberSecurity News

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The Hacker News
· October 3, 2026

AI summary

The Warlock threat actor, believed to be linked to China, is exploiting vulnerabilities in Microsoft SharePoint to attack organizations in countries where Portuguese and Spanish are spoken. The attacks have targeted critical infrastructure, government, and education sectors. The threat actor's activity has been observed by the Symantec and Carbon Black Threat Hunter Team. Warlock is using the exploited vulnerabilities to disable security tools and deploy ransomware. The attacks likely involve both old and new SharePoint vulnerabilities.

Countries in focus

Read the full article at The Hacker Newsthehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.