What happened
Microsoft patched the ToolShell SharePoint Server chain, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771, in July 2025; SharePoint Online is not affected.
On October 2, 2026, reporting based on new Symantec and Carbon Black research described continuing Warlock intrusions through on-premises SharePoint vulnerabilities.
Across the two months before publication, researchers identified at least four affected organisations: a water utility, a telecommunications provider, a regional government body and a university in Portuguese- and Spanish-speaking countries across Europe, Africa and Latin America.
In one detailed intrusion, the attackers disabled protection software on at least 40 hosts in about two hours, deployed Warlock ransomware to 33 hosts through the domain SYSVOL share and took nine days from initial access to the final stage. The reported chain included SharePoint web shells, theft of ASP.NET machine keys, Visual Studio Code tunnelling, a vulnerable K7RKScan driver used to suppress endpoint protection and ransomware staging through SYSVOL. The activity demonstrates that remediation must address retained cryptographic and identity material, not only installed SharePoint updates. The cited weekend reporting did not publish victim names, incident-specific hashes, IP addresses, domains, ransom-payment outcomes or confirmed data-exfiltration findings.
Why this matters now
The vulnerabilities are not new; the decision-changing evidence is that a ransomware operator continues to gain access through them more than a year after patches became available. That turns old remediation debt into a current incident-exposure question, particularly for critical services with long-lived on-premises SharePoint deployments.
The reported sequence reaches beyond the initial web server. Web shells, stolen ASP.NET machine keys, tunnelling, security-tool suppression and SYSVOL staging create routes into identity and domain operations. A patched SharePoint server can remain unsafe if attackers retained machine keys, persistence, credentials or administrative footholds from earlier access.
The affected sectors include water, telecommunications, regional government and education across multiple regions. The sources did not report OT disruption, named victims or ransom outcomes, so leadership should avoid assuming sector-wide compromise while still prioritising exposed SharePoint and recovery dependencies.
The decision for security leaders
Do not accept current patch status as compromise closure. Infrastructure and incident-response teams should establish whether each historically exposed SharePoint server received machine-key rotation, web-shell review, identity containment and sufficient log analysis after ToolShell remediation.
Prioritise organisations with public SharePoint, weak endpoint visibility or critical service dependencies. The campaign’s path from a web application to domain-wide ransomware means the decision owner spans application infrastructure, Active Directory, endpoint security and resilience rather than a single server team.
Validate recovery assumptions against deliberate security-tool suppression and SYSVOL abuse. Recovery plans should identify how domain services, file distribution and endpoint rebuilding continue if shared administrative paths are untrusted.
Evidence of closure
- Asset record proves every on-premises SharePoint farm, version, owner and historical exposure.
- Validation report confirms ToolShell fixes, machine-key rotation and web-shell review.
- Hunt results document driver, tunnel, SYSVOL and endpoint-control evidence across retained telemetry.
- Recovery exercise proves critical services can resume without affected SharePoint or domain distribution paths.
The Security.io assessment
The evidence does not describe a new ToolShell disclosure. It demonstrates continued operational exploitation of old SharePoint weaknesses against organisations that include critical services. That makes historical exposure and post-patch compromise review the material Monday question.
The reported counts show rapid defensive impairment once domain access was established. They do not establish how broadly the campaign operates, whether all four organisations suffered encryption or whether any water or telecommunications operations were disrupted.
Attribution posture: Symantec tracks the operator as Longlegs, Microsoft tracks it as Storm-2603, and the reporting describes a China-linked nexus.
Security.io assigns medium confidence because the campaign chronology and technical sequence originate with established research teams and accountable reporting, but victims remain unnamed and incident-specific indicators, exfiltration findings and operational consequences were not published.
Questions for the morning meeting
- Which on-premises SharePoint servers remain internet-reachable or retain historical exposure?
- Were ASP.NET machine keys rotated after ToolShell remediation?
- Can recovery isolate SYSVOL and preserve domain operations if ransomware staging is detected?