Home › Intelligence › Brief
BREACH BRIEF🟠 High Ransomware

Warlock Ransomware Exploits Zero‑Day SharePoint Flaws to Hit Water Utility, Telecom Operator and Others

Warlock ransomware leveraged four SharePoint zero‑day vulnerabilities to compromise a water utility, telecom provider, regional government and university, disabling AV/EDR on dozens of hosts before encrypting data. The incident highlights the need for continuous vulnerability management and auditable patch‑remediation evidence for compliance readiness.

LiveThreat™ Intelligence · 📅 October 03, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Warlock Ransomware Exploits Zero‑Day SharePoint Flaws to Hit Water Utility, Telecom Operator and Others

What Happened — The China‑linked Warlock ransomware group leveraged a chain of four SharePoint zero‑day vulnerabilities (CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771) to gain initial access to on‑premises SharePoint farms at a water utility, a telecom provider, a regional government body and a university. After establishing footholds, the actors deployed a BYOVD driver (CVE‑2025‑1055) to disable AV/EDR on ~40 hosts, staged the ransomware payload in SYSVOL, and launched Warlock on at least 33 systems.

Why It Matters for Trust & Control Assurance

  • Demonstrates how unpatched application vulnerabilities can bypass traditional perimeter defenses, underscoring the need for continuous vulnerability management and evidence of timely patching.
  • Shows the value of a control‑assurance program that logs remediation actions, validates patch deployment, and provides auditable proof that critical systems are hardened.
  • Highlights the importance of monitoring for abnormal driver loading and AV/EDR disable events as part of an ongoing detection and response control set.

Who Is Affected – Critical infrastructure (water utilities), telecom operators, regional government agencies, and higher‑education institutions that run on‑premises SharePoint deployments.

Recommended Actions

  • Immediately verify that all SharePoint servers are patched for the four ToolShell CVEs; apply Microsoft’s out‑of‑band updates where available.
  • Deploy a continuous control‑mapping solution to track patch status against the “vulnerability remediation” control objective and generate audit‑ready evidence.
  • Enable strict driver‑allow‑list policies and monitor for unsigned or anomalous driver loads; integrate alerts into your SIEM for rapid response.
  • Conduct a focused incident‑response tabletop exercise that includes ransomware containment, AV/EDR restoration, and SYSVOL integrity checks.

Source: BleepingComputer

Technical Notes

  • Attack vector: exploitation of SharePoint zero‑day vulnerabilities (ToolShell) followed by BYOVD driver abuse (CVE‑2025‑1055) to kill AV/EDR.
  • Payload staging in SYSVOL enabled rapid lateral execution via Group Policy.
  • Use of VS Code tunneling and NetExec facilitated remote command execution and credential spraying.

Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/warlock-ransomware-breach-sharepoint-in-water-telecom-operator-attacks/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →