MikhbarMIKHBAR
Cybersecurity

Ransomware Developer Sentenced Amid New AI Security Threats

A week of significant movement in the cybersecurity landscape sees the sentencing of a prolific ransomware creator alongside emerging threats targeting AI agents and critical enterprise infrastructure.

Ransomware Developer Sentenced Amid New AI Security Threats

Ransomware Developer Sentenced to Prison

A Zurich court has delivered a significant blow to cybercriminal operations, handing a nearly 13-year prison sentence to a Ukrainian IT specialist for his role in developing destructive ransomware. According to a recent [sentenced](https://www.swissinfo.ch/eng/swiss-politics/ukrainian-hacker-jailed-in-switzerland-over-ransomware-attacks/92040952) report, the individual was the technical architect behind the Lockergoga, MegaCortex, and Nefilim ransomware families.

The court established that while the developer served more as a technical consultant than a primary mastermind, his efforts directly facilitated extortion attacks against major corporations, including [Stadler Rail](https://www.securityweek.com/railway-vehicle-maker-stadler-hit-malware-attack/). Prosecutors noted that the total financial impact of the campaigns linked to his software is estimated at $123 million.

AI Risks and Emerging Agent Exploits

The cybersecurity landscape is increasingly grappling with vulnerabilities inherent in artificial intelligence. A new zero-click flaw identified as Plugin4Shell has been disclosed by researchers. This vulnerability affects major platforms including Claude Code, OpenAI Codex, GitHub Copilot, and the Gemini CLI. By manipulating plugin repositories, attackers can swap legitimate commits for malicious code without triggering existing SHA-pinning security measures.

This threat is compounded by findings in Mandiant's latest [AI Risk and Resilience report](https://cloud.google.com/security/resources/ai-risk-and-resilience-2026), which details how attackers are shifting toward using autonomous agents for full-scale intrusions. The report documented instances where hijacked coding assistants spread worms across repositories and compromised CI/CD credentials allowed attackers to perform real-time co-debugging of exfiltration tools.

New Information Stealer Targets Bug Bounty Hunters

CrowdStrike has observed a growing trend of financially motivated actors leveraging LLM-generated code to facilitate malicious activity. The security firm identified [PhantomRaven](https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/), an npm-based information stealer that is reportedly authored by an LLM due to its characteristic verbose comments and structure.

The malware, which is distributed through typosquatted packages, harvests CI/CD environment variables. Interestingly, there is no evidence that the stolen data is being sold on illicit markets. Instead, the operator appears to be using the information to identify and report compromises to organizations, effectively 'moonlighting' by leveraging the stolen data to secure bug bounty payouts.

Critical Vulnerability Discovered in SAP Systems

Enterprise organizations are being urged to prioritize updates following the disclosure of a critical vulnerability in SAP software. Security researchers have [warned about CVE-2026-44756](https://pathlock.com/blog/security-alerts/cve-2026-44756-sap-extended-passport-overflow-unauthenticated-memory-corruption-in-the-sap-kernel/), a maximum-severity flaw affecting the Extended Passport processing code. The vulnerability, which researchers have dubbed [OVERPASS](https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/), allows unauthenticated attackers to execute memory corruption before any authentication checks occur.

The flaw impacts a wide array of SAP products including S/4HANA, NetWeaver, and Business Suite. Because remote code execution is confirmed as achievable via HTTP/HTTPS and NGRFC, experts warn that public technical write-ups have significantly lowered the barrier for exploit development, necessitating immediate emergency patching for any internet-facing SAP installations.

Broader Industry Developments

Beyond these specific threats, the broader ecosystem continues to see shifts in policy and funding. A comprehensive [cybersecurity news roundup](https://www.securityweek.com/topics/in-other-news/) published this week highlights that NIST and CISA have released a final report regarding the protection of signed tokens and identity assertions. The guidance is intended to assist federal agencies and cloud providers in securing SSO and API access.

Additionally, the market for AI security continues to heat up. Raindrop, a firm focused on identifying failures in autonomous agents, recently announced a significant [Series A funding round](https://www.businesswire.com/news/home/20260917786051/en/Raindrop-Announces-Series-A-and-%2450M-in-Total-Funding-Led-by-CRV-to-Protect-the-World-from-AI-Agent-Failures) of $35 million. The investment aims to bolster their technology for continuous analysis of agent behavior to prevent silent failures and unauthorized automated actions.

Sources

  • SecurityWeekIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw