Warlock linked to attacks on critical infrastructure
A report published on October 2, 2026, links the Warlock ransomware group to attacks on critical infrastructure in Portuguese- and Spanish-speaking countries, exploiting multiple Microsoft SharePoint vulnerabilities.
A news item published on October 2, 2026, says the Warlock ransomware group was used in attacks on critical infrastructure in Portuguese- and Spanish-speaking countries. It attributes the claim to a new report by the Symantec Threat Hunter Team, which says the group is exploiting multiple vulnerabilities affecting Microsoft SharePoint.
The available excerpt does not identify the vulnerabilities, countries, affected organizations, or technical details of the attacks. To verify the scope and findings, consult the cited report and compare it with the news outlet’s original publication; do not infer affected versions or remediation steps that the sources do not specify.