CyberHighReportedBuilding
6.7
China-linked Warlock ransomware exploits SharePoint in water, telecom attacks
BleepingComputerLO·US · CN·1 day ago
The China-based threat actor Warlock has been actively exploiting SharePoint vulnerabilities since July 2025, with recent expansion into critical infrastructure sectors. The scope of affected organizations and specific sectors remain unclear, but the campaign signals sustained, targeted cyber espionage against high-value targets.
Entities
The China-linked Warlock ransomware group is actively exploiting SharePoint vulnerabilities for initial access, confirmed in attacks against a US water utility, telecom provider, regional government body, and university. This represents an expansion of a sustained campaign targeting critical infrastructure and public sector entities, with the full scope and data impact currently under investigation.