⤷ Title: SharePoint Under Siege: China-Linked Storm-2603 Unleashes Warlock Ransomware After Zero-Day Exploitation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:33:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China #cybersecurity #exploitation #LockBit #ransomware #SharePoint #Storm_2603 #Warlock #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 28 Jul 2025 00:33:29 +0000
════════════════════════
⌗ Tags: #Vulnerability #APT #China #cybersecurity #exploitation #LockBit #ransomware #SharePoint #Storm_2603 #Warlock #zero_day
Penetration Testing Tools
SharePoint Under Siege: China-Linked Storm-2603 Unleashes Warlock Ransomware After Zero-Day Exploitation
Microsoft confirms China-linked Storm-2603 is exploiting SharePoint zero-days (CVE-2025-49706, -49704) to deploy Warlock ransomware on unpatched on-premises servers.
⤷ Title: Storm-2603: SharePoint Zero-Day Exploitation and Warlock Ransomware — A Hybrid Financial and…
════════════════════════
𐀪 Author: Wes Young
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 14:46:01 GMT
════════════════════════
⌗ Tags: #threat_intelligence #cybersecurity #warlock #china #ransomware
════════════════════════
𐀪 Author: Wes Young
════════════════════════
ⴵ Time: Tue, 29 Jul 2025 14:46:01 GMT
════════════════════════
⌗ Tags: #threat_intelligence #cybersecurity #warlock #china #ransomware
Medium
Storm-2603: SharePoint Zero-Day Exploitation and Warlock Ransomware — A Hybrid Financial and Espionage Threat
🚨 SharePoint just became SharePWN: Storm‑2603 blew through three fresh CVEs, torched > 400 orgs (yes, including the U.S. National Nuclear…
⤷ Title: The AK47 Project: New Report Ties Storm-2603 to LockBit and Warlock Ransomware, SharePoint Exploits
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AK47 C2 #china #cybersecurity #LockBit #Project AK47 #ransomware #Sharepoint #Storm_2603 #Unit 42 #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 Aug 2025 00:00:24 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AK47 C2 #china #cybersecurity #LockBit #Project AK47 #ransomware #Sharepoint #Storm_2603 #Unit 42 #Warlock
Daily CyberSecurity
The AK47 Project: New Report Ties Storm-2603 to LockBit and Warlock Ransomware, SharePoint Exploits
In a revelation, Unit 42 has exposed a financially motivated cyber threat actor cluster, dubbed CL-CRI-1040, with dangerous ties to known ransomware operations and links to the Storm-2603 actor pr…
⤷ Title: WarLock Ransomware group Claims Breach at Colt Telecom and Hitachi
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 18 Aug 2025 11:43:31 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Colt #Cyber Attack #data breach #Hitachi #Ransomware #Russia #SharePoint #Vulnerability #WarLock
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Mon, 18 Aug 2025 11:43:31 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #Colt #Cyber Attack #data breach #Hitachi #Ransomware #Russia #SharePoint #Vulnerability #WarLock
Hackread
WarLock Ransomware group Claims Breach at Colt Telecom and Hitachi
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Warlock Ransomware: How a New Group Is Weaponizing Unpatched SharePoint Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 00:40:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Microsoft SharePoint #ransomware #threat intelligence #Trend Micro #Vulnerability #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 21 Aug 2025 00:40:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Microsoft SharePoint #ransomware #threat intelligence #Trend Micro #Vulnerability #Warlock
Daily CyberSecurity
Warlock Ransomware: How a New Group Is Weaponizing Unpatched SharePoint Servers
A new report from Trend Micro details how the Warlock ransomware group is exploiting a vulnerability in unpatched Microsoft SharePoint servers to attack organizations.
⤷ Title: GOLD SALEM: A New Ransomware Group Is Exploiting SharePoint Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:11:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #CVE_2024_51324 #Cybercrime #EDR evasion #GOLD SALEM #ransomware #Sharepoint #Sophos #Warlock Group
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:11:16 +0000
════════════════════════
⌗ Tags: #Malware #BYOVD #CVE_2024_51324 #Cybercrime #EDR evasion #GOLD SALEM #ransomware #Sharepoint #Sophos #Warlock Group
Daily CyberSecurity
GOLD SALEM: A New Ransomware Group Is Exploiting SharePoint Flaws
Sophos uncovers GOLD SALEM, a new ransomware group exploiting SharePoint flaws. The group uses EDR evasion and legitimate tools to attack global targets.
⤷ Title: Warlock Ransomware: How SharePoint Flaws Were Weaponized to Breach Enterprises
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 03:32:50 GMT
════════════════════════
⌗ Tags: #warlock #patch_management #ransomware #sharepoint_vulnerability #cybersecurity
════════════════════════
𐀪 Author: Deven Chhajed
════════════════════════
ⴵ Time: Sun, 12 Oct 2025 03:32:50 GMT
════════════════════════
⌗ Tags: #warlock #patch_management #ransomware #sharepoint_vulnerability #cybersecurity
Medium
Warlock Ransomware: How SharePoint Flaws Were Weaponized to Breach Enterprises
In cybersecurity, the battlefield is rarely where you expect it. Sometimes, it’s not the flashy zero-days or exotic malware strains that…
⤷ Title: Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Oct 2025 00:20:21 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CamoFei #China APT #CVE_2025_53770 #Ransomware_as_a_Service #SharePoint Zero_Day #Warlock Ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 24 Oct 2025 00:20:21 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #BYOVD #CamoFei #China APT #CVE_2025_53770 #Ransomware_as_a_Service #SharePoint Zero_Day #Warlock Ransomware
Daily CyberSecurity
Warlock Ransomware Hits US Firms Exploiting SharePoint Zero-Day, Linked to China’s CamoFei APT
Symantec exposed Warlock ransomware (a probable Anylock rebrand) used by China-linked Storm-2603. It exploits the SharePoint zero-day and BYOVD to disable security and encrypt files with the .x2anylock extension.
⤷ Title: GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:20:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_nexus #DFIR Abuse #GOLD SALEM #LockBit #ransomware #Sharepoint #ToolShell #Velociraptor #Warlock
Daily CyberSecurity
GOLD SALEM Abuses Velociraptor DFIR Tool as Ransomware Precursor Following SharePoint ToolShell Exploitation
GOLD SALEM (Storm-2603) is exploiting SharePoint via ToolShell then abusing the Velociraptor DFIR tool as a ransomware precursor. The group deploys Warlock and LockBit 3.0 variants, often targeting critical infra.
⤷ Title: Shadows in the Server: How the Warlock Group Weaponized a “Forgotten” VM to Breach SmarterTools
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #CVE_2026_23760 #CVE_2026_24423 #Gold Salem #ransomware #SentinelOne #SmarterMail #SmarterTools #Storm_2603 #Tech News 2026 #Warlock Group #zero_day exploit
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:27:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #Active Directory #CVE_2026_23760 #CVE_2026_24423 #Gold Salem #ransomware #SentinelOne #SmarterMail #SmarterTools #Storm_2603 #Tech News 2026 #Warlock Group #zero_day exploit
Penetration Testing Tools
Shadows in the Server: How the Warlock Group Weaponized a "Forgotten" VM to Breach SmarterTools
SmarterTools has disclosed a comprehensive retrospective regarding a recent infiltration of its infrastructure, meticulously delineating the adversaries’ entry