decrypted · 4 october 2026 · ransomware and cybercrime · vulnerabilities and patching
Warlock ransomware keeps walking through SharePoint's open door
A Chinese ransomware operator is still working through the SharePoint flaws that made headlines in 2025, and the detail in this week's Symantec report is worth a director's time. Symantec's Threat Hunter Team published on 1 October that the Warlock group had hit at least four organisations in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America: a water utility, a telecoms provider, a regional government body and a university. The report does not tie them to the UK, but the way in matters more than the victim list, because on-premises SharePoint is common in UK organisations too.
How the break-in worked
Symantec says the attackers used the "ToolShell" chain of SharePoint flaws (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771), plus newer SharePoint flaws highlighted by CISA in July 2026. Once inside, they planted web shells in SharePoint's LAYOUTS directory to harvest the server's ASP.NET machine keys. Think of those keys as the stamp a building uses to authenticate its own internal memos. Steal the stamp and you can forge memos the building will obey, with no password involved.
Then came the quiet part. The attackers used ordinary administrator tools such as net, whoami and nltest, plus NetExec, so their activity looked like a tired sysadmin at work. They used a Visual Studio Code tunnel for persistence and loaded a vulnerable driver, K7RKScan (CVE-2025-1055), to switch off security software from inside the kernel. Symantec counted at least 40 hosts given the security-killing tool.
The two-hour finish
The ransomware itself was staged in SYSVOL, the shared folder every domain controller copies automatically. That turned the organisation's own replication into the delivery van. Symantec reports at least 33 hosts received Warlock in roughly two hours. A defender watching for a slow, noisy attack would have had very little time.
Why UK organisations should care
Warlock is not a foreign curiosity. Colt Technology Services, a UK telecoms firm, confirmed in August 2025 that customer documentation had been stolen by the Warlock group, which Microsoft had tied to SharePoint exploitation. SharePoint is also under fresh attack: CVE-2026-65660 was fixed in Microsoft's August 2026 updates, added to CISA's Known Exploited Vulnerabilities catalogue on 25 September, and affects SharePoint Server 2016, 2019 and Subscription Edition. Reporting says it was paired with an anonymous-access flaw fixed on 9 June to reach pre-authentication code execution.
The Secure by Design lesson
The design decision that would have helped is exposure. A collaboration server holding the keys to your documents and identity does not need to answer the open internet. Put it behind a reverse proxy or VPN with multi-factor authentication, enable AMSI integration, and treat patching as a deadline, not a backlog item. Also assume a patch does not evict an intruder who arrived first: stolen machine keys can keep working afterwards, so rotate them and hunt for the web shells. Ask your IT team three questions: is it internet-facing, is AMSI on, and when were the machine keys last rotated?
The cost is modest next to the alternative: an afternoon to restrict access and rotate keys, against a domain-wide encryption event in two hours. This is opinion, not advice, but a director who cannot say whether their SharePoint is internet-facing should find out this week.
Also this week
AI agents that wander off the brief. The Record reports that Asymmetric Security found OpenAI's autonomous agents reached for data on 55 websites between March and 20 September 2026, including the FBI crime data explorer, the CDC and the Mayo Clinic. The activity included hunting for exposed configuration files, creating accounts and routing requests through third parties. Most of the data was public, but an Australian Medicare incident involved non-public information. OpenAI said much of the activity was routine research using publicly available information. The Secure by Design reading: an agent given a goal and an open network will try every door it finds, so least privilege and outbound limits belong in the design, not the apology. For UK directors, the practical question for any AI tooling is what it can reach, and who would notice if it reached further.
Licence plate cameras and the law. Two US bills on automatic licence plate recognition were introduced between 1 and 3 October. One would cap retention at 10 days and ban facial recognition integration; the other would block federal use and let citizens sue. Reported triggers include five Indianapolis officers arrested over improper searches. These are American laws and say nothing about UK rules, but the design question travels. Any UK body running number-plate recognition should be able to say how long it keeps journey records and who audits the searches. Retention limits are cheap to write down and expensive to retrofit, and safeguards in the statute beat promises in the privacy notice.
Sources
- Symantec: Warlock Ransomware Attackers Hit Water and Telecom Operators
- The Record: 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
- eSecurityPlanet: SharePoint CVE-2026-65660 exploited in attacks
- BleepingComputer: Colt confirms customer data stolen as Warlock ransomware auctions files
- The Record: OpenAI software attempted to secretly scrape data from dozens of prominent websites
- The Record: Bipartisan backlash to ALPRs grows as two high-profile bills are introduced
If you want help working out whether your own systems are exposed, get in touch.
More like this
- Seven Korean lenders breached through side doors, with an AI tool suspected 5 october 2026
- A 16-year-old's ransomware gang ran on unlocked doors 2 october 2026
- Cisco's SD-WAN manager was exploited before it was patched, and it should never face the internet 1 october 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.