Old SharePoint gaps still expose critical services to ransomware
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Monday, October 5th, 2026.
Water, telecom, government, and university organizations remain exposed to ransomware through SharePoint weaknesses disclosed more than a year ago. Warlock operators recently hit at least four organizations across Europe, Africa, and Latin America. They used unpatched SharePoint servers to get inside and then expanded through the Windows domain. In one critical-infrastructure intrusion, the attackers disabled security tools across at least 40 hosts and deployed ransomware to at least 33.
The operation shows how an old internet-facing weakness can become a much wider enterprise incident. The attackers used webshells, stolen SharePoint machine keys, vulnerable signed drivers, Visual Studio Code tunneling, and SYSVOL replication.
For leaders, delayed remediation can turn a known application weakness into disruption across essential operations. For defenders, SharePoint exposure, domain administration, security-tool failures, tunneling services, and replicated files need to be investigated as one connected path. The larger lesson is that known gaps remain valuable when attackers can link them to trusted enterprise systems. Patch or mitigate on-premises SharePoint and hunt for post-compromise activity before declaring the exposure closed.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.