Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 59%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence68
China-linked Warlock operators hit at least four organisations through SharePoint flaws in two months, Symantec says. Its report lists six 2026 SharePoint CVEs only as possible additions, and the entry it documents is still older flaws on servers never patched or mitigated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 68%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
A third party published CVE-2026-63520 before the planned date, and two public gadget chains now reach the same flaw by different routes. One signature will not cover both.
Reality
- Evidence72
- Adoption40
- Hype gap+5
- Incentives45
- Confidence70
A single September 2026 KEV batch produced 1,262,273 GitLab matches and nothing at all for Cisco Secure Firewall Management Center, because the console holding one of the two 10.0 bugs is the one passive scanning cannot fingerprint.
Reality
- Evidence45
- Adoption55
- Hype gap+10
- Incentives70
- Confidence50
ANY.RUN says the kit lures staff with Teams, DocuSign and Dropbox pages, walks them through a genuine device code sign-in, and then takes the access and refresh tokens to register a device of its own.
Reality
- Evidence25
- Adoption20
- Hype gap+45
- Incentives85
- Confidence60
Microsoft Security Research describes callers posing as IT staff to get a Microsoft 365 session relayed or minted to their own client. The lasting damage comes from the MFA method they then register.
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives55
- Confidence55
Only one of the 398 CVEs Microsoft fixed in August was confirmed exploited, and the SharePoint chain now hitting servers turns on a July patch, which puts exposure on cycle lag rather than on ranking.
Reality
- Evidence33
- Adoption44
- Hype gap+16
- Incentives56
- Confidence38
Broadcom's Threat Hunter Team says the same small team, the same infrastructure and one control panel serve both Chinese state espionage and a crypto-fraud sideline. Actor-type triage does not survive that.
Reality
- Evidence58
- Adoption68
- Hype gap+12
- Incentives62
- Confidence55