FR
live
tag

#sharepoint

Warlock ransomware walks through critical-infrastructure SharePoint a year after the ToolShell zero-days

A year after the ToolShell SharePoint zero-days, the China-linked Warlock group — tracked as Longlegs by Symantec — hit a water utility, a telecom operator, a regional government, and a university, disabling protection on 40 machines in two hours. Patch your on-prem SharePoint, monitor BYOVD driver loads, and hunt the indicators published by Symantec and Carbon Black.

CVE-2026-65660 turns Microsoft’s SharePoint ‘spoofing’ flaw into remote code execution

Microsoft described CVE-2026-65660 as a CVSS 6.5 spoofing issue; researcher Dinh Ho Anh Khoa showed it is actually a code-injection flaw (CWE-94) enabling authenticated remote code execution, and CISA added it to the KEV catalog on September 25, 2026 after observed attacks. Apply the August 11 patch and audit your SharePoint 2016, 2019 and Subscription Edition servers.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss