The question
What we told them
Maybe not. A patch closes the hole. It does not remove an attacker who was already inside.
Here is what is happening. On 3 Oct 2026, The Hacker News reported that the Warlock ransomware crew has spent about two months breaking into at least four organizations. The way in was on-premises SharePoint, using the "ToolShell" family of flaws first disclosed in 2025. Two victims ran critical infrastructure: a water utility and a telecom provider. The others were a regional government body and a university.
What came next matters more. In one intrusion, the attackers pushed a tool that switches off security software to at least 40 machines in about two hours. Ransomware then landed on at least 33. The security software was the safety net, and it was cut first.
Two points for a business your size. First, this hits SharePoint Server on a box you run yourself. Microsoft says SharePoint Online in Microsoft 365 is not affected. Second, Microsoft's own advice was to install the update, then rotate the server's ASP.NET machine keys and restart IIS. The web shell these attacks use can steal that key material — and a ticket that says "patched" does not tell you whether the keys were changed too.
Our view: if you still run SharePoint on a server, ask this week for proof the keys were rotated. Then ask whether the server earns its keep. For most small firms it does not. Moving the files to SharePoint Online removes the exposed server entirely. Whatever you decide, set an alert for any machine whose security agent goes quiet. Silence is a signal.
A patch date is not a security status. If you run SharePoint on your own server, ask this week for proof that the machine keys were rotated after patching, and ask whether the server should exist at all. Treat a security agent that stops reporting as an incident.