ThreatPaper
Weak Evidence

Warlock attacks now include newer 2026 SharePoint vulnerabilities

Assessment

The Record reported the attacks 'have continued into 2026 and now include newer SharePoint vulnerabilities' recently spotlighted by the US government, citing CISA's six new SharePoint flaws. The primary research by Symantec names only the 2025 ToolShell set (CVE-2025-49704/49706/53770/53771) as the group's confirmed arsenal, says newer flaws 'likely remain' alongside, and does not pin any specific CVE to the observed July 2026 intrusion. The 'now includes newer CVEs' framing goes beyond what the forensic evidence establishes.

Where this claim appeared

The Record (Recorded Future News) · 2026-10-02

https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Warlock ransomware exploits SharePoint ToolShell flaws to hit water, telecom and government targets

Think this assessment is wrong? Report an error.