VYPR
researchPublished Sep 18, 2026· 1 source

Ransomware Developer Sentenced, SAP Flaw Disclosed, AI Attack Trends Highlighted in SecurityWeek Roundup

A weekly cybersecurity news roundup from SecurityWeek covers the sentencing of a ransomware developer, a critical SAP vulnerability, and emerging AI-driven attack vectors.

SecurityWeek's latest cybersecurity news roundup brings attention to several significant developments, including the sentencing of a ransomware developer, the disclosure of a critical vulnerability in SAP systems, and the growing threat of AI-powered attacks. The article highlights how these diverse events shape the current threat landscape.

In a notable legal development, a Ukrainian IT specialist has been sentenced to nearly 13 years in prison by a Zurich court for developing ransomware families such as Lockergoga, MegaCortex, and Nefilim. These strains were implicated in extortion attacks that caused an estimated $123 million in damages. While the court viewed his role as a technical consultant rather than the operation's mastermind, the sentence underscores the legal consequences for those involved in creating tools for cybercrime.

The cybersecurity community is also grappling with a critical vulnerability in SAP's Extended Passport processing code, identified as CVE-2026-44756 and dubbed OVERPASS. Discovered by Onapsis, this flaw allows unauthenticated attackers to trigger memory corruption before any login checks, potentially leading to remote code execution. The vulnerability affects a wide range of SAP products, including S/4HANA and NetWeaver, and SAP is urging immediate patching, especially for internet-facing systems, given the rapid release of public exploit details.

Emerging threats involving artificial intelligence are also a key focus. Mandiant's AI Risk and Resilience report indicates a shift from attackers using AI for research to employing autonomous agents for entire intrusions. Examples include hijacked coding assistants spreading worms and compromised CI/CD credentials enabling real-time exfiltration tool debugging with LLMs. The report also flags new financial risks, such as an accounting agent's runaway loop causing significant cloud costs.

Further underscoring the evolving nature of cyber threats, a JavaScript information stealer named PhantomRaven, distributed via npm packages, is believed to have been written by an LLM. CrowdStrike attributes this malware to a financially motivated actor who uses it to identify compromises for bug bounty payouts, harvesting system details and CI/CD environment variables.

In other news, five leaders of the Black Axe crime syndicate's Cape Town chapter have been extradited to the U.S. to face charges related to wire fraud and money laundering conspiracy, stemming from romance scams and advance-fee schemes. Additionally, NIST and CISA have released guidance for federal agencies and cloud providers on defending against token theft in cloud environments, focusing on token validation, secrets management, and scaled detection.

Finally, a critical file-upload flaw in the WooCommerce Wholesale Lead Capture WordPress plugin has been exploited, leading to over 100,000 exploit attempts. Attackers can bypass file-type checks to upload webshells. Separately, TP-Link has patched two flaws in its Tapo C200 security camera, including an authentication bypass that grants admin access without a password and a denial-of-service vulnerability.

Synthesized by Vypr AI