Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server
ID: 7e796cd1-8066-562f-806c-d7c2badd1315
STIX ID: report--7e796cd1-8066-562f-806c-d7c2badd1315
Feed Name: The Hacker News
Threat Score
SmarterTools disclosed that the Warlock (Storm-2603) ransomware group breached an unpatched SmarterMail server on January 29, 2026, abusing SmarterMail vulnerabilities (notably CVE-2026-23760 and CVE-2026-24423) to reset admin credentials, mount volumes, deploy Velociraptor, and later execute ransomware; about a dozen Windows servers and hosted SmarterTrack customers were affected, and CISA/third parties confirmed active exploitation and advised immediate upgrades to Build 9526.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
