The threat actor known as Warlock has been actively exploiting SharePoint vulnerabilities since July 2025, according to SecurityWeek. The group, which is based in China, has now expanded its operations to target critical infrastructure organizations.
SecurityWeek reports that Warlock's SharePoint exploitation activity is part of a broader campaign against critical infrastructure. The exact vulnerabilities and methods used were not detailed in the report, but the expansion signals a persistent focus on these high-value targets.
For defenders, the timeline and targeting suggest that SharePoint security should be a priority, especially in critical infrastructure environments. Organizations relying on SharePoint should monitor for related activity and apply patches promptly, as Warlock continues to evolve its tactics.