Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
Summary
The China-based hacking group, referred to as "Warlock," has been actively exploiting SharePoint vulnerabilities since July 2025. This exploitation has been observed in attacks targeting critical infrastructure sectors.
IFF Assessment
FOE
This article details the expansion of a threat actor's exploitation of vulnerabilities in critical infrastructure, posing a direct threat to defenders.
Defender Context
This highlights the ongoing threat of advanced persistent threat (APT) groups targeting critical infrastructure using known vulnerabilities. Defenders should prioritize patching SharePoint instances and remain vigilant for indicators of compromise related to this threat actor.