
Oct 5, 2026 · 7 min
Warlock keeps exploiting old SharePoint flaws worldwide
Warlock continues SharePoint exploits, ShinyHunters member flips China's AI espionage
The campaign shows how unpatched enterprise software can expose critical infrastructure and public institutions long after vulnerabilities emerge.
- 1Warlock continues targeting year-old SharePoint vulnerabilities across utilities, telecom providers, governments, and universities worldwide.
- 2A detained ShinyHunters member reportedly cooperated with the FBI to identify other members of the cybercrime group.
- 3TA419 targeted U.S. AI policy experts in a China-aligned espionage campaign involving Anthropic-related interests.
Don't miss
The report that Saif al-Din Qader, identified as a ShinyHunters member, reportedly cooperated with the FBI after detention.
The brief
Warlock continues exploiting year-old SharePoint vulnerabilities against water utilities, telecommunications providers, governments, and universities worldwide, including organizations in Portuguese- and Spanish-speaking regions.
The SharePoint campaign underscores a familiar security problem: vulnerabilities can remain operationally dangerous long after disclosure, especially across institutions with complex, distributed systems.
The episode also reports that Saif al-Din Qader, identified as a ShinyHunters member, was detained and cooperated with the FBI in efforts to identify others.
A separate China-aligned espionage campaign targeted U.S. AI policy experts, bringing cybersecurity concerns into the policy debate surrounding Anthropic and artificial intelligence.
Together, the stories show how ransomware, cybercrime investigations, and state-aligned espionage are exploiting different points of institutional dependence on technology and information.