BleepingComputer reported on October 2 that Warlock, which Symantec tracks as Longlegs, hit a water utility, a telecom provider, a regional government body, and a university. Initial access was on-prem SharePoint, the ToolShell family first abused in 2025. Symantec's threat-intelligence note is the technical source I used next to that article.

In one July 22 intrusion the actor disabled protection on at least 40 hosts in about two hours and launched Warlock on at least 33. Researchers say the crew staged the payload in SYSVOL, used VS Code Insiders tunneling, and deployed an EDR-killer through a signed vulnerable driver.

SharePoint is still the door more than a year after ToolShell. Water and telecom names make this a critical-infrastructure story. Two hours to blind the floor, then ransomware as soon as the killer lands. The tunneling trick is a developer tool used as remote access. If I still ran on-prem SharePoint, I would patch the ToolShell set and pull internet-facing admin surfaces.