Home › Intelligence › Brief
BREACH BRIEF🟠 High Ransomware

Warlock Ransomware Exploits Unpatched SharePoint Vulnerabilities in Critical Infrastructure Across Portuguese‑ and Spanish‑Speaking Nations

A China‑based group used the Warlock ransomware to breach water utilities, telecoms, universities, and regional governments by exploiting unpatched Microsoft SharePoint flaws. The campaign underscores the importance of robust vulnerability‑management and audit‑ready evidence for control assurance.

LiveThreat™ Intelligence · 📅 October 02, 2026· 📰 therecord.media
🟠
Severity
High
RW
Type
Ransomware
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
4 recommended
📰
Source
therecord.media

Warlock Ransomware Exploits Unpatched SharePoint Vulnerabilities in Critical Infrastructure Across Portuguese‑ and Spanish‑Speaking Nations

What Happened – A China‑based threat group has been using the Warlock ransomware to compromise critical‑infrastructure operators in Portuguese‑ and Spanish‑speaking countries. The attackers repeatedly exploit unpatched Microsoft SharePoint flaws (including the “ToolShell” chain and newer 2025‑2026 vulnerabilities) to gain footholds, disable security tools, and deploy ransomware.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of inadequate vulnerability‑management and patch‑remediation – a core control objective that continuous‑control programs are built to enforce and evidence.
  • Highlights the need for defensible audit evidence that SharePoint instances are regularly scanned, patched, and that remediation actions are logged.
  • Aligns with the Control Mapping capability, which helps organizations collect, correlate, and present remediation evidence across frameworks.

Who Is Affected – Water utilities, telecommunications providers, universities, and regional governments across Europe, Africa, and Latin America.

Recommended Actions

  • Inventory all SharePoint deployments and verify they are patched against the 2025‑2026 advisories.
  • Deploy automated vulnerability scanning and integrate findings into a continuous‑control monitoring platform.
  • Document remediation steps and retain logs as audit‑ready evidence of due diligence.
  • Review and test incident‑response playbooks for ransomware containment on SharePoint‑derived footholds.

Source: The Record

Technical Notes

  • Attack vector: exploitation of multiple SharePoint CVEs (including “ToolShell” and newer 2025/2026 bugs).
  • Ransomware payload: Warlock, delivered after disabling endpoint security tools.
  • Data types: operational documents, network credentials, and potentially sensitive government or utility data.

Source: Symantec Threat Hunter Team report

📰 Original Source
https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →