In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

A Trio of Cybersecurity Stories Highlights Growing Threats to Businesses and Individuals Alike

In a series of concerning developments, cybersecurity experts are sounding the alarm on emerging threats that could have far-reaching consequences for organizations and individuals alike. From the rise of sophisticated AI-powered attacks to the exploitation of critical vulnerabilities in widely used software, these stories underscore the need for vigilance and proactive measures to stay ahead of the bad actors.

One of the most striking examples is the escalating threat posed by agentic attacks. According to Mandiant’s latest AI Risk and Resilience report, attackers are increasingly leveraging autonomous agents to carry out complex intrusions. In some cases, these agents have been used to spread malware across multiple repositories or even to co-debug exfiltration tools with large language models (LLMs) in real-time. This represents a significant escalation of the threat landscape, as attackers are now able to exploit the very systems designed to support and enhance human productivity.

Raindrop, an AI agent monitoring tool that raised $35 million in funding this week, is working to address some of these concerns by continuously analyzing agent behavior to identify emerging failure modes. However, the Mandiant report highlights the urgent need for organizations to adopt more robust defenses against agentic attacks, which could have devastating consequences if left unchecked.

Meanwhile, a financially motivated actor has been linked to an npm-based information stealer called PhantomRaven. This JavaScript malware is distributed through typosquatted packages and harvests system details and CI/CD environment variables from popular development platforms like GitHub Actions and CircleCI. While the stolen data may not be sold on the dark web, it’s being used to flag compromises for bounty payouts – a worrying trend that underscores the growing threat of financially motivated actors in the cybersecurity landscape.

In other news, five leaders of Nigeria’s Black Axe crime syndicate have been extradited from South Africa to face wire fraud and money laundering conspiracy charges. The group ran romance scams and advance-fee schemes against US victims between 2011 and 2021, highlighting the ongoing threat posed by organized cybercrime groups.

A Ukrainian IT specialist has also been sentenced to nearly 13 years in prison for developing ransomware used in extortion attacks on companies including Stadler Rail. The court identified him as the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware families, although his role was described as more technical consultant than mastermind.

Finally, a critical vulnerability has been discovered in SAP’s Extended Passport processing code (CVE-2026-44756), which allows unauthenticated attackers to trigger memory corruption before any login check occurs. Researchers from Onapsis and others have confirmed that this flaw can be exploited remotely over HTTP/HTTPS or NGRFC, with public technical write-ups released within 48 hours of the patch potentially lowering the bar for exploit development.

As these stories demonstrate, the cybersecurity landscape is becoming increasingly complex and fraught with danger. Organizations must remain vigilant and proactive in defending against emerging threats, from agentic attacks to critical vulnerabilities in widely used software. By staying informed and taking steps to protect themselves, individuals can also play a crucial role in mitigating the impact of these threats.

One key takeaway from these stories is the importance of robust defenses against financially motivated actors, who are increasingly using stolen data for bounty payouts rather than selling it on the dark web. Organizations should be particularly cautious when dealing with sensitive data and CI/CD environment variables, which can be exploited by attackers to gain unauthorized access or disrupt business operations.

Ultimately, these stories serve as a reminder that cybersecurity is an ongoing challenge that requires continuous vigilance and proactive measures to stay ahead of the bad actors. By staying informed and taking steps to protect themselves, individuals and organizations can help mitigate the impact of emerging threats and create a safer online environment for all.


Source: SecurityWeek — 2026-09-18