Home › Intelligence › Brief
BREACH BRIEF🟠 High Ransomware

Warlock Ransomware Exploits Unpatched SharePoint Flaws to Target Critical Infrastructure

Warlock ransomware (Longlegs) continues to breach water utilities, telecoms, governments and universities by exploiting legacy SharePoint vulnerabilities. The attacks highlight the need for robust vulnerability‑management controls and audit‑ready evidence for compliance programs.

LiveThreat™ Intelligence · 📅 October 04, 2026· 📰 securityaffairs.com
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
2 recommended
📰
Source
securityaffairs.com

Warlock Ransomware Exploits Unpatched SharePoint Flaws to Target Critical Infrastructure

What Happened — The Warlock ransomware group (aka Longlegs) continues to breach organizations by exploiting unpatched SharePoint vulnerabilities first disclosed in 2025. In the past two months the attackers compromised a water utility, a telecom provider, a regional government body, and a university across Europe, Africa, and Latin America.

Why It Matters for Trust & Control Assurance

  • Unpatched SharePoint servers illustrate a gap in vulnerability‑management controls that continuous assurance programs are built to detect and remediate.
  • The use of a signed but vulnerable driver to disable security tools shows the need for evidence‑based monitoring of privileged software changes.
  • Mapping this exploit to a single control objective (vulnerability management) provides audit‑ready evidence across multiple frameworks (e.g., NIST CSF, ISO 27001).

Who Is Affected – Critical‑infrastructure operators (water utilities), telecom carriers, government agencies, and higher‑education institutions.

Recommended Actions – Conduct a rapid inventory of all SharePoint instances, verify patch levels against the latest Microsoft security bulletins, and capture remediation evidence in a continuous control‑assurance platform. Validate that privileged driver installations are logged and reviewed. Source: https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html

Technical Notes – Initial access is achieved via exploitation of legacy SharePoint zero‑days (ToolShell chain). Attackers plant a webshell in the LAYOUTS directory, steal ASP.NET machine keys, and use DLL sideloading to run payloads downloaded from legitimate hosting services. A signed driver (K7RKScan) is used to disable security software before ransomware deployment. Source: https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html

📰 Original Source
https://securityaffairs.com/200304/malware/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →