
Warlock Group Broadens SharePoint Exploitation
A China-based hacking group tracked as Warlock has expanded its exploitation of Microsoft SharePoint vulnerabilities into attacks on critical infrastructure operators, according to reporting published October 2, 2026. SecurityWeek reports the group has been exploiting SharePoint flaws since July 2025 and is now applying that access against a wider set of targets, including organizations that run industrial or essential-services systems.
Microsoft SharePoint is a widely used on-premises and cloud platform for document management and internal collaboration, which makes it a common entry point into corporate networks when left unpatched. Because many organizations run SharePoint servers on-premises with direct ties to internal file shares, identity systems, and line-of-business applications, a compromised SharePoint instance can give an attacker a foothold well beyond the document library itself.
Where This Fits: The 2025 SharePoint Vulnerability Wave
The exploitation window described in this report traces back to a series of on-premises SharePoint vulnerabilities that came to light in July 2025, when Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA) warned that multiple vulnerabilities were being actively exploited in the wild. CISA added several SharePoint flaws from that disclosure to its Known Exploited Vulnerabilities (KEV) catalog, which lists vulnerabilities that CISA has confirmed are being used in real-world attacks and that federal agencies are required to remediate on a set timeline.
At the time, Microsoft's own security research attributed exploitation of these flaws to multiple China-based actors, and researchers reported that ransomware activity tracked as Warlock followed in some of these intrusions. The new reporting indicates that activity tied to Warlock has not faded since 2025; instead, the group appears to be applying the same SharePoint access techniques against a broader, higher-stakes set of targets more than a year after the initial disclosures.
That persistence matters operationally: it means organizations that patched SharePoint once in mid-2025 cannot assume the threat has passed. Unpatched or re-exposed SharePoint servers, as well as servers compromised before patching occurred, remain viable footholds for this activity.
Key Takeaway
If your organization runs an on-premises SharePoint server, especially one connected to operational technology, patient data, or financial systems, confirm it is fully patched against the 2025 SharePoint vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog, and check logs for signs of compromise predating that patch. A patched server today does not rule out a foothold planted before the fix was applied.
What This Means for Healthcare Practices, Tax Firms, and Small Businesses
Critical infrastructure is the headline target in this report, but the exploitation technique, abusing unpatched SharePoint servers to gain network access, applies just as well to a mid-size medical practice, an accounting firm, or any small business running an on-premises SharePoint deployment. These organizations often hold sensitive patient records, tax filings, or financial data on the same servers used for everyday document sharing, which makes a compromised SharePoint instance a direct path to regulated data.
Practical steps worth taking now:
- Inventory your SharePoint footprint. Confirm whether you run SharePoint Server on-premises versus SharePoint Online in Microsoft 365. On-premises deployments carry the patching burden locally and are the ones affected by the 2025 vulnerability wave.
- Verify patch status against CISA's KEV catalog. Cross-check your SharePoint version and installed updates against the entries in CISA's Known Exploited Vulnerabilities catalog rather than assuming an update months ago covered every relevant flaw.
- Hunt for pre-patch compromise. If your SharePoint server was internet-facing and unpatched at any point after July 2025, review authentication logs, new administrative accounts, and web shell indicators rather than treating a current patch as proof the server was never accessed.
- Segment SharePoint from sensitive systems. Limit SharePoint server access to only the accounts and network segments that need it, so a compromised server cannot pivot directly into financial, patient-record, or operational systems.
- Enable and centralize logging. Ship SharePoint and Windows event logs to a central location your team actually reviews, since on-premises servers often lack the automatic monitoring built into cloud services.
What to Watch Next
Expect follow-up advisories if Warlock's expanded activity is confirmed to involve new vulnerabilities rather than the known 2025 flaws; watch for updates from Microsoft Security Response Center and new additions to CISA's KEV catalog. Organizations in sectors CISA designates as critical infrastructure, including healthcare, energy, water, and financial services, should treat any SharePoint-related advisory as high priority given this group's documented pattern of returning to the same access vector over time.
Bellator Cyber Guard will continue tracking developments in this campaign. In the meantime, the most effective defense remains unglamorous but proven: know what SharePoint deployments you run, confirm they are patched against known exploited vulnerabilities, and assume a server exposed during the 2025 disclosure window deserves a compromise check, not just a patch check.
People also look for
Keep exploring Incident response & NIST
Build a response process that helps people detect, contain, recover, and improve when something goes wrong.
- Common question: incident response planBuild an incident response planStart with clear roles, escalation steps, evidence handling, and recovery priorities.
- Common question: NIST incident response frameworkUse the NIST incident response frameworkWalk through preparation, detection, containment, recovery, and lessons learned.
- Common question: NIST cybersecurity framework guideUnderstand NIST CSF 2.0Connect governance and risk decisions to identify, protect, detect, respond, and recover.
- Common question: cyber incident response plan templateUse an incident response templateTurn response concepts into a document your team can follow under pressure.
- Common question: tax data breach responsePrepare a tax-practice response planAdd IRS, client-data, and tax-season considerations to the general response process.
Learn first. Decide when you are ready.
Keep learning, or apply this to your situation
Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.



