Find notable cyber news and cases, enriched with sources, timelines, and signals.

Warlock ransomware post-exploitation tooling upgrades

Malware Activity
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an observed January intrusion, operators stayed inside a victim network for 15 days before launching ransomware. The group is also using NSecKrnl.sys to terminate security products at the kernel level, while reusing Velociraptor, Cloudflare tunnels, and disguised Rclone for resilient remote access and exfiltration. The activity strengthens persistence, lateral movement, and defense evasion after entry through unpatched Microsoft SharePoint servers.

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score46 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score78 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)

Vulnerability
H score82 First: 14.07.2026 23:25 Last: 14.07.2026 23:25 Sources 1

About this happening: CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts *...

Latest development: 15.07.2026 12:20

Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.

Microsoft releases RoguePlanet Defender security update for CVE-2026-50656

Security Patch Release
H score32 First: 17.06.2026 20:36 Last: 17.06.2026 20:36 Sources 1

About this happening: Microsoft has released a security update for CVE-2026-50656, remediating RoguePlanet in the Microsoft Malware Protection Engine (mpengine.dll). The flaw is a *...

Latest development: 09.07.2026 11:48

Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

Timeline

  1. 17.03.2026 17:36 2 articles · 4mo ago

    Warlock expands SharePoint post-exploitation tooling

    Technical Analysis Update

    Warlock, also tracked as Water Manaul, continued exploiting unpatched Microsoft SharePoint servers and expanded its post-compromise toolkit with BYOVD abuse of the NSecKrnl.sys driver, TightVNC, Yuze, Velociraptor, a Cloudflare tunnel, and Rclone disguised as TrendSecurity.exe. An early January intrusion began at the SharePoint worker process (w3wp.exe) on a compromised server, and the operators remained inside the victim network for 15 days before executing ransomware.

    Show sources