PGH Networks

Warlock Ransomware and the SharePoint Server Risk for SMBs

October 4, 2026· PGH Networks Team· 5 min readCloud & Microsoft 365
Warlock Ransomware and the SharePoint Server Risk for SMBs

What happened

A threat actor tracked as Warlock, suspected to be China-linked, is continuing to weaponize vulnerabilities in Microsoft SharePoint to break into organizations, disable their security tooling, and deploy ransomware. The activity was observed by the Symantec and Carbon Black Threat Hunter Team and reported via feeds.feedburner.com in Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware.

Per that reporting, the victims observed so far have been in Portuguese- and Spanish-speaking countries, spanning critical infrastructure, government, and education. The researchers indicate the group is likely using both older and newer SharePoint flaws. Note what is not established in the reporting: the specific CVEs in play, whether any fully patched server has been compromised, and whether the targeting will stay regional. Treat those as items to verify with your IT provider rather than assumptions to act on. The safe read is that internet-reachable SharePoint Server remains an actively exploited entry point.

cable network

Why this matters for Pittsburgh small and mid-sized businesses

The geography in this report is a snapshot, not a boundary. Ransomware crews that build a working playbook against a product rarely stop at a language border — and SharePoint Server is sitting in a lot of Western Pennsylvania server rooms. We still find on-prem SharePoint farms at CPA firms that stood one up for workpaper libraries a decade ago, at law firms using it for matter folders, at manufacturers who publish drawings and work instructions to the plant floor, and at defense contractors who kept data on-prem specifically to control where it lives. Many of those farms are no longer anybody's job. They run, so nobody touches them.

That is exactly the profile attackers want. The pattern described in the reporting — exploit the web-facing application, then turn off the security tools, then encrypt — is brutal for a 40-person firm because SharePoint usually isn't an isolated box. It's domain-joined, it holds service accounts with broad rights, and it's indexed to half your file estate. An attacker who lands there is one hop from your accounting system and your backup server.

The compliance consequences land differently by vertical, and they land fast:

  • Healthcare: ePHI in a SharePoint library makes this a HIPAA Security Rule problem, with breach notification clocks that start at discovery, not at cleanup.
  • Defense contractors: if controlled unclassified information touched that server, you're looking at DFARS 7012 incident reporting within 72 hours and a very uncomfortable conversation about your CMMC Level 2 assessment evidence.
  • Financial services and accounting: FTC Safeguards obligations assume you have an inventory of systems holding customer information and a documented response plan. "We forgot that server existed" fails both tests.
  • Professional services with SOC 2 reports: unpatched, internet-exposed infrastructure is a control failure your auditor will write up even if nothing was stolen.

One more Pittsburgh-specific wrinkle: a lot of local firms are mid-migration. Mail and Teams moved to the cloud years ago, but the file server and SharePoint farm stayed behind. That half-finished state is the most dangerous configuration, because the on-prem piece gets the least attention and the least budget.

What to do about it this week

  1. Confirm whether you actually run SharePoint Server. SharePoint Online in Microsoft 365 is not affected by on-prem server vulnerabilities and is patched by Microsoft. If your answer is "I'm not sure," that is the finding. Get a written inventory of every on-prem server and which ones answer from the internet.
  2. Verify patch level against Microsoft's current guidance, not your memory. Ask for the installed cumulative update and build number for each SharePoint server and compare it to what Microsoft lists today. Partial patching is common on multi-server farms — the web front end gets updated and the application server doesn't.
  3. Take it off the public internet. If external SharePoint access isn't a hard business requirement, put it behind VPN or a conditional-access-gated reverse proxy this week. This single change removes most of the opportunistic exposure while you work the patching.
  4. Check that your security tooling can't be silently switched off. Tamper protection on, alerts on service-stop events, and a named human who notices within minutes rather than Monday morning. If nobody is watching overnight, that is the gap EDR with 24/7 MDR exists to close.
  5. Audit the SharePoint service accounts. Look for domain admin rights, non-expiring passwords, and reused credentials. Scope them down to least privilege. This is what turns a single-server incident into a company-wide one.
  6. Prove a restore, don't assume one. Pull a test restore of a SharePoint content database and a file share to isolated storage. Confirm at least one backup copy is immutable or offline so it can't be encrypted alongside production.
  7. Pre-write the notification math. For each regulated data type you hold, document today who you'd call and within how many hours. If an incident started on October 4, 2026, a 72-hour DFARS report is due by October 7 — you don't want to be reading the clause for the first time that week.

If item 1 surfaces servers nobody owns, that's a roadmap conversation, not a ticket. Our vCIO engagements exist to retire that kind of debt on a schedule and a budget instead of under duress.

How we help

PGH Networks keeps on-prem and cloud infrastructure current through disciplined patch management and continuous monitoring, hardens or retires legacy SharePoint and file-server workloads, and backs it with layered cybersecurity, immutable backup, and documented compliance evidence for HIPAA, SOC 2, FTC Safeguards, and CMMC. If you don't know whether you're running SharePoint Server today, we'll find out and tell you plainly what the exposure looks like.

Call 724.888.7007 or reach us through the contact form to schedule a SharePoint and external-exposure review.

Share

Related reading

Call usBook a meeting