Warlock Ransomware Exploits Zero‑Day SharePoint Flaws to Hit Water Utility, Telecom Operator and Others
Warlock ransomware leveraged four SharePoint zero‑day vulnerabilities to compromise a water utility, telecom provider, regional government and university, disabling AV/EDR on dozens of hosts before encrypting data. The incident highlights the need for continuous vulnerability management and auditable patch‑remediation evidence for compliance readiness.
ADTP Breach Watch· October 2, 2026· BleepingComputer
SeverityHigh
Type🏛️ Ransomware
ConfidenceHigh
ReportedOct 2, 2026
Energy & UtilitiesWater utilitiesTelecom operatorsRegional government agenciesUniversitiesVulnerability Exploit
What happened
The Warlock group used the ToolShell chain of SharePoint CVEs to gain initial access, deployed a BYOVD driver (CVE‑2025‑1055) that disabled protection on ~40 hosts, staged the ransomware payload in SYSVOL, and launched Warlock on at least 33 systems across four organizations.
Why it matters for trust and compliance
This breach illustrates why a continuous control‑assurance program must capture patch‑deployment evidence and monitor for abnormal driver activity, providing a defensible audit trail for vulnerability‑remediation controls.
Demonstrates the need for real‑time evidence that critical patches are applied across on‑premises applications.
Shows the value of monitoring driver‑load events as part of a broader detection and response control set.
Who is affected
Water utilitiesTelecom operatorsRegional government agenciesUniversities
Recommended actions
Patch all SharePoint servers for CVE‑2025‑49704, CVE‑2025‑49706, CVE‑2025‑53770, CVE‑2025‑53771 and apply any out‑of‑band updates.
Implement a continuous control‑mapping platform to track remediation status and generate audit‑ready evidence.
Enforce driver‑allow‑list policies and integrate AV/EDR‑disable alerts into your SIEM.
Run a ransomware‑focused tabletop exercise covering containment, restoration, and SYSVOL integrity verification.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.