Skip to main content
CyberReportedHighDevelopingFeatured
6.7

China-linked Warlock group expands SharePoint exploitation in critical infrastructure attacks

The China-based threat actor Warlock has been actively exploiting SharePoint vulnerabilities since July 2025, with recent expansion into critical infrastructure sectors. The scope of affected organizations and specific sectors remain unclear, but the campaign signals sustained, targeted cyber espionage against high-value targets.

SecurityWeek1 day agoCN, USengCredibility 25%View source

Score Breakdown

Mosaic Score6.7
Model confidence0.5
Significance0.8
Source credibility0.3
Source

Part of 2 situations

Related signals

8 found