Warlock ransomware walks through critical-infrastructure SharePoint a year after the ToolShell zero-days
A year after the ToolShell SharePoint zero-days, the China-linked Warlock group — tracked as Longlegs by Symantec — hit a water utility, a telecom operator, a regional government, and a university, disabling protection on 40 machines in two hours. Patch your on-prem SharePoint, monitor BYOVD driver loads, and hunt the indicators published by Symantec and Carbon Black.