Warlock Ransomware Exploits Unpatched SharePoint Vulnerabilities in Critical Infrastructure Across Portuguese‑ and Spanish‑Speaking Nations
A China‑based group used the Warlock ransomware to breach water utilities, telecoms, universities, and regional governments by exploiting unpatched Microsoft SharePoint flaws. The campaign underscores the importance of robust vulnerability‑management and audit‑ready evidence for control assurance.
ADTP Breach Watch· October 2, 2026· The Record
SeverityHigh
Type🏛️ Ransomware
ConfidenceHigh
ReportedOct 2, 2026
Energy & UtilitiesTelecommunicationsHigher EducationGovernmentVulnerability ExploitRansomware
What happened
The threat actor leveraged several unpatched SharePoint CVEs—including the ToolShell chain and newer 2025‑2026 bugs—to gain footholds in critical‑infrastructure organizations, disable security tools, and deploy Warlock ransomware.
Why it matters for trust and compliance
This incident tests the control objective of timely vulnerability remediation and patch management, a requirement that maps to multiple frameworks and can be demonstrated through continuous evidence collection.
Provides a concrete example of why continuous monitoring of patch status is essential for audit readiness.
Shows how documented remediation actions create defensible evidence of due diligence across critical assets.
Who is affected
Energy & UtilitiesTelecommunicationsHigher EducationGovernment
Recommended actions
Conduct a full inventory of SharePoint instances and verify patch levels against the latest advisories.
Implement automated vulnerability scanning with continuous‑control monitoring to capture remediation evidence.
Retain detailed logs of patch deployment and validation for audit purposes.
Update ransomware incident‑response playbooks to include SharePoint‑derived compromise scenarios.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.