Microsoft says the Storm-2603 threat group is using SharePoint flaws to launch Warlock ransomware attacks. The group disables Microsoft Defender, steals credentials with Mimikatz, and spreads across networks via PsExec and WMI. More than 400 organizations—including the U.S. Energy Department and the NNSA—have suffered breaches. Microsoft urges admins to patch vulnerable SharePoint servers now, warning that more attackers are already exploiting the same public proof-of-concept exploits.