Water and telecom operators hit as ransomware abuses trusted systems
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 2nd, 2026.
Water, telecom, government and education organizations face operational disruption as Warlock ransomware continues exploiting on-premises SharePoint systems. During the past two months, the campaign compromised at least four organizations: a water utility, a telecommunications provider, a regional government body and a university.
The attackers planted web shells, extracted machine keys and used legitimate cloud and remote-access services to make their activity look more routine. In one intrusion, they pushed a tool to at least 40 hosts to terminate security software. Warlock then reached at least 33 systems after the attackers placed its payload in a trusted domain share. Normal replication helped distribute it across the environment.
This shows how one exposed collaboration server can become the starting point for domain-wide disruption. Recovery plans need to account for attackers turning trusted administration and directory services against the business. Defenders should hunt for web shells, rotate machine keys, restrict SharePoint exposure and review unusual activity in trusted remote-access tools. Contain exposed SharePoint servers, hunt across the domain and validate clean recovery before restoring operations. Patching alone may not remove persistence established before remediation.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.