Cybersecurity Headlines
Cybersecurity Headlines

Oct 5, 2026 · 7 min

Warlock keeps exploiting old SharePoint flaws worldwide

Warlock continues SharePoint exploits, ShinyHunters member flips China's AI espionage

The campaign shows how unpatched enterprise software can expose critical infrastructure and public institutions long after vulnerabilities emerge.

3 key takeaways
  1. 1Warlock continues targeting year-old SharePoint vulnerabilities across utilities, telecom providers, governments, and universities worldwide.
  2. 2A detained ShinyHunters member reportedly cooperated with the FBI to identify other members of the cybercrime group.
  3. 3TA419 targeted U.S. AI policy experts in a China-aligned espionage campaign involving Anthropic-related interests.

Don't miss

The report that Saif al-Din Qader, identified as a ShinyHunters member, reportedly cooperated with the FBI after detention.

The brief

Warlock continues exploiting year-old SharePoint vulnerabilities against water utilities, telecommunications providers, governments, and universities worldwide, including organizations in Portuguese- and Spanish-speaking regions.

The SharePoint campaign underscores a familiar security problem: vulnerabilities can remain operationally dangerous long after disclosure, especially across institutions with complex, distributed systems.

The episode also reports that Saif al-Din Qader, identified as a ShinyHunters member, was detained and cooperated with the FBI in efforts to identify others.

A separate China-aligned espionage campaign targeted U.S. AI policy experts, bringing cybersecurity concerns into the policy debate surrounding Anthropic and artificial intelligence.

Together, the stories show how ransomware, cybercrime investigations, and state-aligned espionage are exploiting different points of institutional dependence on technology and information.

Listen to the full episode and explore every guest, topic, and moment on PodLume.

Warlock keeps exploiting old SharePoint flaws worldwide · PodLume