Trusted Enterprise Control Planes Are Active Attack Surfaces
Citrix NetScaler and Cisco SD-WAN Manager exploitation remain high-consequence examples of attackers targeting trusted, internet-facing management planes. New Warlock reporting on SharePoint exploitation adds a ransomware path involving security-tool disabling, BYOVD, SYSVOL staging, and VS Code tunnels, reinforcing the need for forensic preservation, isolation, credential rotation, and recovery validation—not patching alone.
Sources (8)
Updated Oct 4, 2026