Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2902+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
NEWS

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

A ransomware developer gets 13 years, a zero-click Plugin4Shell flaw hits AI coding agents, and a max-severity SAP bug enables pre-auth RCE.

Dylan H.

News Desk

September 18, 2026
3 min read

A roundup of notable stories that might otherwise have slipped under the radar this week.

Ransomware Developer Sentenced to Nearly 13 Years

A Zurich court sentenced a Ukrainian IT specialist to nearly 13 years in prison for developing ransomware strains including Lockergoga, MegaCortex, and Nefilim. The court identified him as "the lead developer," though it noted his role more closely resembled "a technical consultant rather than the operation's mastermind." Prosecutors estimated total damages at roughly $123 million. The verdict is subject to appeal.


Plugin4Shell: A Zero-Click Flaw in AI Coding Agents

Researchers disclosed Plugin4Shell, a zero-click vulnerability affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. The flaw allows an attacker who controls a plugin repository to swap a previously reviewed, approved commit for malicious code without triggering SHA-pinning checks. Because affected tools apply plugin updates via silent background auto-update, a compromised version can install itself with no user interaction at all.

Anthropic and OpenAI have shipped patches. Microsoft has not yet patched Copilot, and Google has stated the deprecated Gemini CLI will not receive a fix. Teams relying on any of the unpatched tools should review plugin auto-update settings and pin dependencies where possible until fixes land.


Critical SAP "OVERPASS" Flaw — CVE-2026-44756

A maximum-severity vulnerability in SAP's Extended Passport processing, dubbed OVERPASS and tracked as CVE-2026-44756, allows unauthenticated attackers to trigger memory corruption before login verification even occurs. The bug enables remote code execution over both HTTP/HTTPS and NGRFC, and affects S/4HANA, NetWeaver, and Business Suite deployments.

Public technical details were released within 48 hours of the patch shipping, meaningfully lowering the bar for exploitation — SAP customers on affected products should prioritize patching immediately rather than waiting for a routine maintenance window.


Also This Week

  • Raindrop raised a $35 million Series A for tooling that detects autonomous AI agent failures
  • Mandiant's 2026 AI risk report documents attackers using AI agents to run entire intrusions end-to-end — in one case, a single corrupted value drove $50,000 in unplanned cloud costs
  • PhantomRaven, an LLM-generated npm infostealer, was found in use by a bug-bounty hunter harvesting CI/CD credentials
  • Five leaders of a Cape Town-based crime syndicate tied to the Black Axe network were extradited to New Jersey on romance-scam and money-laundering charges
  • NIST and CISA published new guidance on protecting SSO tokens and identity assertions in cloud environments
  • A critical file-upload flaw in a widely used WooCommerce plugin has seen over 100,000 exploitation attempts since its February disclosure
  • Authentication-bypass and denial-of-service flaws were disclosed in TP-Link Tapo C200 security cameras

Sources

  • SecurityWeek — In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
#Ransomware#AI Security#SAP#Supply Chain#Cybercrime

Related Articles

Max Severity SAP Commerce Cloud Flaw Now Targeted in Attacks

A critical RCE vulnerability in SAP Commerce Cloud, patched just days ago, is already being actively exploited in the wild.

3 min read

TeamPCP Hits SAP npm Packages With 'Mini Shai-Hulud' Supply

The threat actor TeamPCP has compromised multiple npm packages tied to SAP's cloud application development ecosystem in a new supply chain campaign dubbed...

4 min read

SAP-Related npm Packages Compromised in Credential-Stealing

Security researchers have uncovered a coordinated supply chain attack campaign dubbed 'mini Shai-H' targeting SAP-related npm packages, injecting...

4 min read
Back to all News