# SharePoint attacks spread Warlock ransomware across essential-service networks

_Published Thursday, October 1, 2026 at 11:08 AM EDT · Security · Latest · Tier 2 — Notable_

![SharePoint attacks spread Warlock ransomware across essential-service networks — Primary](https://cybersecuritynews.com/wp-content/uploads/2026/10/Warlock-Ransomware-Exploiting-SharePoint-Flaws.webp)

A threat actor exploiting Microsoft SharePoint Server compromised at least four organizations over the past two months, including a water utility and a telecommunications provider, according to Symantec research reported by Cybersecurity News. The victims also included a regional government body and a university across Europe, Africa and Latin America.

The operator, tracked by Symantec as Longlegs, extracts cryptographic keys from SharePoint to forge requests that execute code. In one intrusion, attackers distributed ransomware through SYSVOL, a shared directory that replicates across domain controllers, reaching at least 33 systems. They also abused Visual Studio Code tunnels for covert access. Investigators did not conclusively identify the vulnerable driver used to disable security tools in that intrusion.

## Sources

- [cybersecuritynews.com](https://cybersecuritynews.com/warlock-ransomware-exploiting-sharepoint-flaws/)

---
Canonical: https://techandbusiness.org/newswire/DSv6KXjJqiW8X8VFGbAHTb
Published: 2026-10-01T15:08:28.573Z
Story chronology: 2026-10-01T14:14:26.000Z
Retrieved: 2026-10-01T17:30:31.971Z
Publisher: Tech & Business (techandbusiness.org)
