Le groupe derrière le ransomware Warlock continue de s'introduire dans les organisations par le biais de serveurs Microsoft SharePoint. Parmi ses victimes récentes figurent des opérateurs d'infrastructures critiques, une administration régionale et une université, selon un nouveau rapport de Symantec.
Au cours des deux derniers mois, l'opérateur a compromis au moins quatre organisations dans des pays lusophones et hispanophones. D'après Symantec, il s'agit d'un service des eaux, d'un fournisseur de télécommunications, d'une administration régionale et d'une université.
Qui se cache derrière Warlock
Warlock serait exploité par un groupe basé en Chine que Symantec suit sous le nom de Longlegs. D'autres chercheurs le désignent sous le nom de Storm-2603. Le groupe a été rattaché à des opérations connues sous les noms de CL-CRI-1040, CamoFei et ChamelGang.
The group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint servers. Its recent victims include critical infrastructure operators, a regional government body and a university, according to a new report from Symantec.
Over the past two months, the operator has compromised at least four organizations in Portuguese- and Spanish-speaking countries. Symantec says the victims were a water utility, a telecommunications provider, a regional government body and a university.
Who is behind Warlock
Warlock is thought to be run by a China-based group that Symantec tracks as Longlegs. Other researchers call it Storm-2603. The group has been connected to operations known as CL-CRI-1040, CamoFei and ChamelGang.
Cybercriminals are actively trying to recruit employees inside target organizations, because staff with legitimate access can bypass security controls that are hard to defeat from the outside. This is according to Intel 471's new report, Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services.
The threat intelligence firm found that routine tasks such as looking up information, resetting accounts, approving transactions or changing shipments are being packaged and sold as services to criminal customers.
Recruitment dominates the sample
Intel 471 analyzed 85 records. Recruitment was the largest category, with 45 records. Another 15 involved claims of insider capability, 11 of them claims of insider access. Twelve records advertised services allegedly enabled by employee privileges. The rest covered access and data offerings, a recruitment guide and a complaint.
Google has added six features to Advanced Protection in Android 17. One of them targets a familiar problem in spyware investigations: the evidence often disappears from the phone once the attacker cleans up.
The question matters most to people such as journalists, who may suspect their device has been compromised and then find nothing left to examine. The new release addresses this by keeping a copy of security records away from the handset itself. People already using Advanced Protection will get a notification when the new capabilities reach their devices.
Logs that survive a cleanup
The headline feature is Intrusion Logging. It records security and network events on the device, including app activity. If a user suspects a compromise, they can download the logs, decrypt them and hand them to trusted security experts for analysis.
Organizations are writing policies for AI tools, but many cannot enforce them when an agent actually acts. That is the main finding of Delinea's 2026 Identity Security Report: The AI Enforcement Gap. The report describes AI agents that keep their permissions long after their work is finished.
The report surveyed IT and security leaders as well as employees. Identity security teams said they are worried about two things: the ongoing access AI agents have to company systems, and the actions these agents take on behalf of users.
"Written policy is only as good as your ability to enforce it at the moment an AI agent acts," said Art Gilliland, CEO of Delinea. "Our research echoes what I hear from leaders constantly: they have the AI policies in place, but they can't see or report on what their agents actually do."
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.