A Ransomware Developer’s Downfall, AI-Driven Attacks on the Rise, and Critical SAP Flaw Exposed
In a significant win for cybersecurity efforts, a Ukrainian IT specialist has been sentenced to nearly 13 years in prison by a Zurich court for developing ransomware used in extortion attacks on companies. The verdict marks a major milestone in the fight against cybercrime, with estimated damages from the campaign totaling around $123 million.
The convicted individual was identified as the lead developer behind several notorious ransomware families, including Lockergoga, MegaCortex, and Nefilim. While his role was described as closer to that of a technical consultant than the mastermind, the sentence sends a strong message about the consequences of engaging in such activities. The case highlights the growing need for law enforcement agencies to work together with cybersecurity experts to track down and prosecute those responsible for developing and distributing malware.
Meanwhile, another worrying trend is emerging: AI-driven attacks are escalating rapidly. A recent report from Mandiant finds that attackers have moved beyond prompting AI chatbots for research and are now using autonomous agents to run entire intrusions. One notable example cited in the report involved a hijacked coding assistant helping spread a self-propagating worm across around 100 repositories. Another incident saw an attacker co-debug exfiltration tools with a Large Language Model (LLM) in real-time, highlighting the dangers of AI-driven attacks.
The rise of AI-powered malware is also reflected in the development of information-stealing malware like PhantomRaven. This JavaScript-based tool, distributed through typosquatted npm packages, harvests system details and CI/CD environment variables from various platforms, including GitHub Actions and CircleCI. While the stolen data does not appear to be sold on criminal marketplaces, it is likely used by the operator to flag compromises for bounty payouts.
In related news, a group of five leaders of the Cape Town chapter of Nigeria’s Black Axe crime syndicate have been extradited from South Africa to face wire fraud and money laundering conspiracy charges. The group ran romance scams and advance-fee schemes against US victims between 2011 and 2021.
The cybersecurity landscape is also facing another critical threat: a maximum-severity flaw in SAP’s Extended Passport processing code, known as CVE-2026-44756 or OVERPASS. Unauthenticated attackers can exploit this vulnerability to trigger memory corruption before any login check occurs, with remote code execution achievable over HTTP/HTTPS and NGRFC.
As organizations using SAP are urged to patch this critical vulnerability, it is essential for them to take a proactive approach to their cybersecurity posture. This includes implementing robust security controls, conducting regular vulnerability assessments, and staying up-to-date with the latest threat intelligence.
Ultimately, the recent developments serve as a reminder of the evolving nature of cyber threats. As AI-driven attacks escalate, it is crucial for organizations to be vigilant and adopt a layered defense approach that incorporates cutting-edge technologies and strategies. By doing so, they can mitigate the risks associated with these emerging threats and stay ahead of the attackers.
Source: SecurityWeek — 2026-09-18