BREACH WATCH BRIEF High 🏛️ Ransomware

Warlock Ransomware Exploits Unpatched SharePoint Vulnerabilities in Critical Infrastructure Across Portuguese‑ and Spanish‑Speaking Nations

A China‑based group used the Warlock ransomware to breach water utilities, telecoms, universities, and regional governments by exploiting unpatched Microsoft SharePoint flaws. The campaign underscores the importance of robust vulnerability‑management and audit‑ready evidence for control assurance.

SeverityHigh
Type🏛️ Ransomware
ConfidenceHigh
ReportedOct 2, 2026
Energy & Utilities Telecommunications Higher Education Government Vulnerability Exploit Ransomware

What happened

The threat actor leveraged several unpatched SharePoint CVEs—including the ToolShell chain and newer 2025‑2026 bugs—to gain footholds in critical‑infrastructure organizations, disable security tools, and deploy Warlock ransomware.

Why it matters for trust and compliance

  • This incident tests the control objective of timely vulnerability remediation and patch management, a requirement that maps to multiple frameworks and can be demonstrated through continuous evidence collection.
  • Provides a concrete example of why continuous monitoring of patch status is essential for audit readiness.
  • Shows how documented remediation actions create defensible evidence of due diligence across critical assets.

Who is affected

Energy & Utilities Telecommunications Higher Education Government

Recommended actions

  1. Conduct a full inventory of SharePoint instances and verify patch levels against the latest advisories.
  2. Implement automated vulnerability scanning with continuous‑control monitoring to capture remediation evidence.
  3. Retain detailed logs of patch deployment and validation for audit purposes.
  4. Update ransomware incident‑response playbooks to include SharePoint‑derived compromise scenarios.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.