Warlock attacks now include newer 2026 SharePoint vulnerabilities
Assessment
The Record reported the attacks 'have continued into 2026 and now include newer SharePoint vulnerabilities' recently spotlighted by the US government, citing CISA's six new SharePoint flaws. The primary research by Symantec names only the 2025 ToolShell set (CVE-2025-49704/49706/53770/53771) as the group's confirmed arsenal, says newer flaws 'likely remain' alongside, and does not pin any specific CVE to the observed July 2026 intrusion. The 'now includes newer CVEs' framing goes beyond what the forensic evidence establishes.
Where this claim appeared
The Record (Recorded Future News) · 2026-10-02
https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacksWhat “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Warlock ransomware exploits SharePoint ToolShell flaws to hit water, telecom and government targetsThink this assessment is wrong? Report an error.