FR
live
tag

#toolshell

Warlock ransomware walks through critical-infrastructure SharePoint a year after the ToolShell zero-days

A year after the ToolShell SharePoint zero-days, the China-linked Warlock group — tracked as Longlegs by Symantec — hit a water utility, a telecom operator, a regional government, and a university, disabling protection on 40 machines in two hours. Patch your on-prem SharePoint, monitor BYOVD driver loads, and hunt the indicators published by Symantec and Carbon Black.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss