Your collaboration farm can still fire the software that was supposed to catch ransomware.
That is the ugly operational fact in this week’s Warlock cluster, and it should reset how you fund cybersecurity. Symantec and Carbon Black’s Threat Hunter Team say a suspected China-linked crew is still weaponizing Microsoft SharePoint flaws against Portuguese- and Spanish-speaking critical infrastructure, government, and education networks. The interesting part of the chain is the middle. After the foothold, they disable security tools, then they encrypt.
You already knew SharePoint was a beachhead. The new failure mode is authority. The farm sits close enough to your threat-protection stack that a web shell can turn agents off. That is a design choice you made, even if nobody wrote it down.

Collab Hosts Still Own Your Stack
Most shops still run SharePoint as an intranet with a security afterthought. Farm accounts have local admin on the box. The box can talk to every endpoint management channel you own. Backup, AV, and inventory service accounts sit in the same forest because the installer asked for it.
Give an operator that graph and they skip the clever implant. They disable threat detection the same way your helpdesk does, with the same rights, from a server you marked as trusted.
Ask your EDR console who is allowed to uninstall. If SharePoint’s hostname, the farm account, or the jump box that admins the farm is on that list, you already lost the argument.
Warlock’s targeting maps to shops that left that graph intact. Critical infrastructure, government, and education in Portuguese- and Spanish-speaking countries. Long patch queues. Shared admin workstations. A lot of Microsoft collab that never got treated like a domain controller.
Your firewall may be doing honest work at the edge. It still passes a kill command from an allowed SharePoint host on an allowed management port. East-west trust is doing the attacker a favor.
Brute-force against the farm’s admin paths is still in play on the noisy jobs. The quieter jobs skip guessing. They reuse a stolen farm credential or a SharePoint RCE and inherit whatever the service account can already touch.
If the farm can uninstall EDR, the farm is in your incident.
Cybersecurity Catalogs Arrive Late
The same Saturday, SANS ISC noted YARA-X 1.21.0. Five improvements. Four bugfixes. That is useful work if your scanners are alive. It does nothing for a host whose agent was killed from Central Administration an hour earlier.
Signatures do not reboot a killed agent.
Vendors will still sell you the 2026 story. The Hacker News roundup of “The State of Cybersecurity in 2026” talks about cloud sprawl, identities, and continuous visibility. Fine. Visibility is a property of sensors you still control. A collab RCE that can mute those sensors turns your SIEM into a museum of last-known-good.
This is a bad look for any program that measures cyber security by rule-pack freshness. You can be current on YARA and still lose the weekend because the SharePoint box had rights your EDR console trusted.
Defense in depth here means the collab tier cannot be a security admin. Network policy, local rights, and backup control planes have to survive an intranet compromise. If your only copy of “what good looks like” lives on the same forest the farm can rewrite, you are one web shell away from a dark SOC.
Cut the Farm’s Right to Fire Tools
Security hardening on this class of incident is mostly subtraction. Pull the collab host out of the groups that can tamper with agents. Then prove it with a test you would hate to run in production, because the attacker is already running it.
Do these now, on the live farm, not in a strategy deck:
- Immediate: Isolate internet-facing SharePoint from endpoint-management networks. Deny the farm computer account from stopping services, unloading drivers, or calling any EDR uninstall API. If you cannot state that path as a deny, treat it as an allow.
- Immediate: Rotate farm, IIS app-pool, and content-database credentials. Treat every SharePoint admin session from the last 14 days as hostile until you can prove otherwise. Open incident response on the collab host as a privileged identity.
- Immediate: Hunt for security-tool service stops, driver unloads, and tamper-protection flips that originated from SharePoint IPs or farm service accounts. That timeline is your start of encryption, even if files still look fine.
- Ongoing: Put a host-firewall ipban on repeated failures against Central Administration and the farm’s PowerShell endpoints so brute-force dies on the box. Replicate those blocks with ipbanpro persistence across nodes so a reboot does not reopen the management path.
- Ongoing: Split backup catalogs and restore consoles onto identities the SharePoint farm cannot read or disable. Test a restore in a lab after you mute EDR on purpose. If backups die when tools die, you do not have backups.
Keep doing the boring weekly work. Patch the farm. Remove leftover web shells. Cut NTLM where you can. None of that replaces the rights cut. The rights cut is the control that survives the next SharePoint CVE, including the ones you have not numbered yet.
You will still want better threat detection.
Buy it. Just stop letting the intranet fire it.
Sources
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- YARA-X 1.21.0 Release
- The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
