Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

Summary

The China-based hacking group, referred to as "Warlock," has been actively exploiting SharePoint vulnerabilities since July 2025. This exploitation has been observed in attacks targeting critical infrastructure sectors.

IFF Assessment

FOE

This article details the expansion of a threat actor's exploitation of vulnerabilities in critical infrastructure, posing a direct threat to defenders.

Defender Context

This highlights the ongoing threat of advanced persistent threat (APT) groups targeting critical infrastructure using known vulnerabilities. Defenders should prioritize patching SharePoint instances and remain vigilant for indicators of compromise related to this threat actor.

Read Full Story →