BREACH WATCH BRIEF High 🏛️ Ransomware

Warlock Ransomware Exploits Zero‑Day SharePoint Flaws to Hit Water Utility, Telecom Operator and Others

Warlock ransomware leveraged four SharePoint zero‑day vulnerabilities to compromise a water utility, telecom provider, regional government and university, disabling AV/EDR on dozens of hosts before encrypting data. The incident highlights the need for continuous vulnerability management and auditable patch‑remediation evidence for compliance readiness.

SeverityHigh
Type🏛️ Ransomware
ConfidenceHigh
ReportedOct 2, 2026
Energy & Utilities Water utilities Telecom operators Regional government agencies Universities Vulnerability Exploit

What happened

The Warlock group used the ToolShell chain of SharePoint CVEs to gain initial access, deployed a BYOVD driver (CVE‑2025‑1055) that disabled protection on ~40 hosts, staged the ransomware payload in SYSVOL, and launched Warlock on at least 33 systems across four organizations.

Why it matters for trust and compliance

  • This breach illustrates why a continuous control‑assurance program must capture patch‑deployment evidence and monitor for abnormal driver activity, providing a defensible audit trail for vulnerability‑remediation controls.
  • Demonstrates the need for real‑time evidence that critical patches are applied across on‑premises applications.
  • Shows the value of monitoring driver‑load events as part of a broader detection and response control set.

Who is affected

Water utilities Telecom operators Regional government agencies Universities

Recommended actions

  1. Patch all SharePoint servers for CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771 and apply any out‑of‑band updates.
  2. Implement a continuous control‑mapping platform to track remediation status and generate audit‑ready evidence.
  3. Enforce driver‑allow‑list policies and integrate AV/EDR‑disable alerts into your SIEM.
  4. Run a ransomware‑focused tabletop exercise covering containment, restoration, and SYSVOL integrity verification.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.