The China-linked Warlock ransomware group has reportedly targeted a water utility, telecom provider, regional government body, and university by exploiting SharePoint vulnerabilities for initial access.
BleepingComputer reported that the activity has recently focused on Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America. The report is another reminder that internet-facing collaboration platforms can become a direct entry point when security updates lag behind active exploitation.
Why it matters
Organizations using SharePoint should validate patch levels, reduce external exposure where possible, and investigate signs of anomalous web activity or follow-on access in environments that may be affected.
Source: BleepingComputer, October 2, 2026
