BREACH WATCH BRIEF High 🏛️ Ransomware

Warlock Ransomware Exploits Unpatched SharePoint Flaws to Target Critical Infrastructure

Warlock ransomware (Longlegs) continues to breach water utilities, telecoms, governments and universities by exploiting legacy SharePoint vulnerabilities. The attacks highlight the need for robust vulnerability‑management controls and audit‑ready evidence for compliance programs.

SeverityHigh
Type🏛️ Ransomware
ConfidenceHigh
ReportedOct 4, 2026
Energy & Utilities Critical‑infrastructure utilities Telecom service providers Government agencies Higher‑education institutions Vulnerability Exploit

What happened

The Longlegs group used unpatched SharePoint zero‑day flaws to gain initial access, planted webshells, stole ASP.NET machine keys, and deployed ransomware after disabling security tools with a vulnerable signed driver.

Why it matters for trust and compliance

  • The incident underscores the importance of continuous vulnerability‑management and patch‑verification controls that can be mapped to a single control objective, providing evidence for multiple compliance frameworks.
  • Demonstrates a control gap in vulnerability management that continuous monitoring can surface and remediate.
  • Provides audit‑ready evidence of patch status and privileged driver usage for framework‑aligned compliance.

Who is affected

Critical‑infrastructure utilities Telecom service providers Government agencies Higher‑education institutions

Recommended actions

  1. Inventory all SharePoint servers and verify they are patched to the latest Microsoft releases.
  2. Enable continuous monitoring of privileged driver installations and capture remediation evidence in a control‑assurance platform.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.