In other news: Ransomware developer convicted, Plugin4Shell AI attack, critical SAP flaw

In other news: Ransomware developer convicted, Plugin4Shell AI attack, critical SAP flaw

Weekly from SecurityWeek Cybersecurity News Summary provides a succinct overview of key developments that may not be covered entirely in isolation but are nonetheless relevant to the broader threat landscape.

This curated summary highlights key stories about vulnerability disclosures, new attack vectors, policy updates, industry reports and other notable events to help readers stay well-informed about the evolving cybersecurity environment.

Here are this week’s highlights:

Raindrop raises $35M to monitor AI agents

Raindrop, designed to detect unknown errors in autonomous agents, announced a Series A financing round of $35 million, an addition to last year’s seed round of $15 million. Raindrop continuously analyzes agent behavior to uncover silent and emerging failure modes and help AI systems repair and learn from them.

Advertising. Scroll to continue reading.

Mandiant’s 2026 AI Risk Report highlights the escalation of agent attacks

The latest from Mandiant AI Risk and Resilience Report notes that attackers have moved away from asking AI chatbots to do research and instead letting autonomous agents carry out complete interventions. It cites incidents in which a hijacked coding wizard helped spread a self-propagating worm across approximately 100 repositories, and a compromised CI/CD credential allowed an attacker to debug exfiltration tools alongside an LLM in real time. Separately, the report highlights a new category of financial risk, describing a case in which a damaged asset sent an accountant into an out-of-control thinking loop that caused over 15,000 API calls and approximately $50,000 in cloud costs in less than an hour.

Npm info stealer author benefits from bug bounty programs

CrowdStrike has an NPM-based information stealer called “ PhantomRaven to a financially motivated actor who moonlights as a bug bounty hunter. The JavaScript malware distributed through typosquatted npm packages is classified with high confidence as being written by an LLM due to its verbose comments and wildcard code, and collects system details and CI/CD environment variables from GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike has found no evidence that the stolen data is being sold on criminal marketplaces, suggesting the operator is simply using it to indicate compromises in bounty payouts.

Black Ax leader extradited to US over cybercrime network

Five leaders of the Cape Town branch of the Nigerian Black Ax crime syndicate were there delivered from South Africa to New Jersey, where they face charges of wire fraud and money laundering conspiracy. Prosecutors say the group ran romance scams and advance payment schemes against U.S. victims from 2011 to 2021. The defendants, who were arrested in South Africa in 2021, also face related wire fraud and identity theft charges related to the compromise of business emails.

Ransomware developer sentenced to 13 years in prison in Switzerland

A Zurich dish sentenced A Ukrainian IT specialist has been sentenced to almost 13 years in prison for developing ransomware used in extortion attacks on companies such as Stadler Rail. The court identified him as the lead developer of the Lockergoga, MegaCortex and Nefilim ransomware families, but described his role as a technical advisor rather than a mastermind of the operation. Prosecutors estimated the campaign’s total damages at about $123 million, and the verdict is still subject to appeal.

NIST and CISA detail defenses against token theft in the cloud

NIST and CISA have published a final joint study report Provide implementation guidance to federal agencies and cloud providers to protect the signed tokens and identity assertions underlying single sign-on, federation, and API access. The report addresses token validation, secrets management, and detection at scale, taking into account feedback collected by CISA’s Joint Cyber ​​Defense Collaborative on an earlier draft. It builds on existing NIST guidance on security and privacy controls and supports the principles of Secure by Design.

Organizations warned of critical SAP security vulnerability

Organizations using SAP were Warning about CVE-2026-44756A high-severity flaw in Extended Passport processing code that allows unauthenticated attackers to trigger a memory corruption before a login verification takes place. Onapsis discovered the vulnerability and named it OVERPASS. Researchers at Pathlock and nullFactor confirmed in lab tests that remote code execution is possible over HTTP/HTTPS and NGRFC, and warned that public technical reports released within 48 hours of the patch lower the bar for exploit development. The flaw affects a wide range of SAP products, including S/4HANA, NetWeaver and Business Suite. SAP is pushing for emergency patches for Internet-connected systems.

WordPress plugin error causes bulk webshell uploads

Defiant says attackers did it exploited a critical file upload flaw in the WooCommerce Wholesale Lead Capture plugin that blocked more than 100,000 exploit attempts since the flaw was announced in February. The flaw allows unauthenticated visitors to bypass file type checks and upload PHP webshells because the plugin trusts a list of allowed extensions provided by the attacker rather than its own configuration. Website owners are urged to update to version 2.0.3.2 and check for suspicious PHP files, especially in the uploads directory.

TP-Link fixes the Tapo camera bug that skips password checks

OPSWAT researchers found two Defects in the TP-Link Tapo C200 surveillance cameraincluding an authentication bypass that allows an attacker on the network to replay a value from the camera’s challenge-response process to gain administrative access without a password. A second flaw allows a denial of service attack by sending oversized Wi-Fi credentials during device onboarding, causing the camera’s HTTPS service to crash. TP-Link fixed both issues, tracked as CVE-2026-15315 and CVE-2026-15316, in firmware V5_1.4.6 released in August.

Automatic plugin updates enable silent takeover by AI agents

Researchers at Air’s safety lab announced Plugin4Shella zero-click flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI that allows an attacker controlling a plugin’s repository to swap a pinned, verified commit for malicious code without triggering the SHA pinning check. Because the affected agents check out a requested commit without checking what actually landed, an attacker can name a branch after the pinned hash, causing Git to resolve it instead and automatic background updates to push the malicious version to already installed plugins without user intervention. Anthropic and OpenAI have shipped fixes for Claude Code and Codex, Microsoft hasn’t patched Copilot yet, and Google says it won’t fix the outdated Gemini CLI at all.

Related: In other news: InjectEave attack, SIM swapper convicted, Glasswing findings review

Related: In other news: Microsoft’s cloud patches, hacked Dropbox accounts, Guardio’s $1.1 billion worth

Leave a Reply

Your email address will not be published. Required fields are marked *