Warlock ransomware reaches water and telecom operators through SharePoint
Symantec says the China-nexus Longlegs group, also known as Storm-2603, compromised a water utility, a telecommunications provider, a regional government body and a university. The attackers exploited on-premises SharePoint vulnerabilities, harvested ASP.NET machine keys and used a signed driver to disable security tools before deploying Warlock ransomware.
Why it matters to you
SharePoint compromise can become domain-wide quickly: in one case, the attackers pushed an EDR-disabling tool to 40 hosts in roughly two hours and staged ransomware in SYSVOL. Patch supported servers, rotate SharePoint machine keys, restart IIS, hunt for web shells and review domain-controller, endpoint and network telemetry stored outside the affected estate.
Fake Zoom installer delivers a persistent macOS backdoor
Jamf Threat Labs identified CloudSyncD, a backdoor packaged inside a disk image designed to resemble the Zoom installer. The lure asks users to bypass Gatekeeper and enter their macOS password, then installs a universal Mach-O implant that communicates with live command-and-control infrastructure.
Why it matters to you
Trusted brand names and a familiar installer layout do not establish software authenticity. Obtain collaboration tools from managed distribution or vendor-owned domains, prevent standard users from bypassing Gatekeeper, and monitor unexpected launch agents, privileged installer activity and encrypted outbound beacons.
AWS commits $1 billion as data-centre resistance becomes a capacity risk
AWS will spend more than $1 billion over five years in US communities hosting its data centres, including support for energy affordability, water preservation, education and job training. Amazon says more than 100 proposed data-centre moratoriums are under consideration nationwide.
Why it matters to you
Compute capacity depends on community approval, power prices and water availability as well as servers and network links. Treat announced regions as provisional until permits and energisation are confirmed, and retain alternate deployment regions for SaaS services that cannot wait for delayed capacity.
European firms expect to finance AI mainly from their own cash
An ECB survey of about 5,000 euro-area firms found that 72% planning AI investment expect to use cash flow or retained earnings. Training is a priority for 46% and data infrastructure for 40%, while bank loans, grants and leasing each appear in only 16% of financing plans.
Why it matters to you
For a European SaaS builder, the practical constraint is often cash flow rather than model access. Stage AI investment behind measurable customer outcomes, favour usage-based infrastructure, budget for staff training and avoid locking scarce capital into hardware or long contracts before demand is proven.
AI infrastructure may require $4.2 trillion in new revenue within five years
Reuters reports that global data-centre spending could exceed $30 trillion by 2050. Bain estimates infrastructure builders must find more than $4.2 trillion of new revenue within five years, while economists warn that broad productivity gains have not yet caught up with the pace of investment.
Why it matters to you
Infrastructure announcements increasingly depend on aggressive utilisation and revenue assumptions. Evaluate providers' debt, committed versus planned capacity and customer concentration; keep workloads portable and calculate cost per completed SaaS task rather than relying on token prices or headline benchmarks.