Microsoft: SharePoint flaws exploited in Warlock ransomware attacks
ID: 93cb8615-859c-53d2-984c-5365158bd133
STIX ID: report--93cb8615-859c-53d2-984c-5365158bd133
Feed Name: Bleeping Computer
**Executive summary:** A China-based threat actor tracked as Storm-2603 is actively exploiting multiple SharePoint zero-day vulnerabilities (ToolShell chain including CVE-2025-49706, CVE-2025-49704, CVE-2025-53770) to deploy Warlock (and previously LockBit) ransomware; attackers use Mimikatz, PsExec, Impacket, WMI and GPO modifications to move laterally and encrypt systems, with reports of hundreds of compromised SharePoint servers and breaches affecting multiple U.S. and international government entities, while Microsoft and CISA have issued patches and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
