Skip to the stories
Saturday, 3 October 2026
Saved

Next edition

0:33

Headlines

Cybersecurity

China-linked group Warlock exploits SharePoint flaws to deploy ransomware

A suspected China-linked threat actor named Warlock is exploiting Microsoft SharePoint vulnerabilities to disable security tools and deploy ransomware against organizations in Portuguese- and Spanish-speaking countries.

FTMQ News, written by our newsroom

Picture: The Hacker News

The Hacker News reported that a threat group known as Warlock is continuing to exploit vulnerabilities in Microsoft SharePoint. The group, which is suspected of having links to China, targets organizations located in Portuguese-speaking and Spanish-speaking countries. [1]

According to the Hacker News, the attackers are likely using both old and new SharePoint security flaws. During the intrusions, Warlock disables security tools installed on the systems before deploying ransomware across the compromised networks. [1]

Wikipedia describes ransomware as malware that takes private data hostage until a ransom is paid. This form of extortion can involve encrypting files or exfiltrating data with threats to release it publicly. Attackers usually demand payments through cryptocurrency or stored-value cards, which are harder to trace and complicate prosecution. In some cases, victims can recover original files without paying if the software contains implementation mistakes, lacks encryption, or if cryptographic keys leak. [4]

Computer security is defined by Wikipedia as a field that focuses on protecting software, systems, and networks from threats. These threats can lead to data theft, hardware damage, or service disruption. Security tools are designed to block unauthorized access, but malicious actors seek to disable them during cyberattacks. [3]

In short

  • Warlock is a suspected China-linked threat group targeting organizations in Portuguese- and Spanish-speaking countries.
  • The group exploits both old and new Microsoft SharePoint vulnerabilities.
  • Warlock disables security tools on victim networks before deploying ransomware.
  • Ransomware holds private data hostage through encryption or exfiltration until a ransom is paid.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy RansomwareThe Hacker News, 3h ago (the report this story comes from)

Background

  1. [2]Karnak (character) on Wikipedia
  2. [3]Computer security on Wikipedia
  3. [4]Ransomware on Wikipedia

Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record.

Earlier reports of ours on the same people and subjects.

More in Cybersecurity