Warlock ransomware gang breaches water, telecom and government networks via SharePoint flaws
Symantec and Carbon Black researchers say the China-linked Warlock group, also tracked as Longlegs, has compromised a water utility, a telecom provider, a regional government body and a university by exploiting on-premises SharePoint vulnerabilities, including the ToolShell exploit chain. In one July 22 intrusion, the attacker disabled security software on roughly 40 hosts within two hours and deployed Warlock ransomware to at least 33 machines, using a signed but vulnerable driver to kill endpoint defenses.