Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
Summary
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.