Colt Technology faces multi-day outage after WarLock ransomware attack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-53770 | Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×3 |
| mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users |
Full article357 words · extracted from securityaffairs.com · click to collapse

WarLock ransomware hit Colt Telecom, causing outages in hosting, porting, Colt Online, and Voice API since August 12.
UK-based Colt Technology Services suffered a cyberattack, reportedly caused by WarLock ransomware, resulting in multi-day outages for hosting, porting, Colt Online, and Voice API services.
Colt, officially known as Colt Technology Services Group Limited, is a multinational telecommunications company headquartered in London, United Kingdom. It was founded in 1992 as City Of London Telecommunications and initially focused on building a telecoms network in London. Over time, Colt expanded its operations across Europe, Asia, and North America.
The compant specializes in providing high-performance connectivity and communication solutions for businesses. Its services include data, voice, cloud, and managed IT services, with a focus on delivering scalable, secure, and reliable network infrastructure. Colt owns and operates a large fiber-optic network connecting thousands of buildings across multiple cities and countries through metropolitan and long-haul networks.
The firm serves a wide range of business clients, from large multinational corporations to smaller enterprises, and operates in over 40 countries with more than 6,000 employees. Colt is known for its strong commitment to customer service, innovation, and sustainability.
Threat actors put stolen data up for sale. The incident began on August 12, and disruptions persist as the company’s IT teams work nonstop to contain the impact and restore affected systems.
Colt initially described the disruption as a “technical issue” but later confirmed it was a cyberattack. The firm shut down systems to mitigate the threat. The company pointed out that Core network infrastructure was not impacted. The company has notified authorities but shared no technical details on the attack, and there is still no timeline for restoring operations.
The popular cybersecurity expert Kevin Beaumont believes that threat actors likely breached sharehelp.colt.net via Microsoft SharePoint flaw CVE-2025-53770, then remained within its network for over a week. The researcher also speculates that Colt is trying to cover it up.
A WarLock affiliate, “cnkjasdfgd,” claimed the attack, offering 1M stolen documents for $200K, including financial, employee, customer, and internal data.


Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, WarLock ransomware)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181247/data-breach/colt-technology-faces-multi-day-outage-after-warlock-ransomware-attack.html