A Swiss court has sentenced a Ukrainian IT specialist to nearly 13 years in prison for his role in developing ransomware used in attacks against organizations, including rail manufacturer Stadler Rail. The Zurich court linked the defendant to the Lockergoga, MegaCortex, and Nefilim ransomware families. While the court characterized him as a technical contributor rather than the leader of the operations, prosecutors estimated losses associated with the campaigns at approximately $123 million. The decision can be appealed.
Separately, organizations running SAP software have been urged to prioritize remediation of CVE-2026-44756, a maximum-severity vulnerability affecting Extended Passport processing. The issue, dubbed OVERPASS by Onapsis, could allow an unauthenticated attacker to trigger memory corruption before authentication checks take place. Researchers said remote code execution was achievable in test environments through HTTP, HTTPS, and NGRFC. SAP products potentially affected include S/4HANA, NetWeaver, and Business Suite, with internet-exposed deployments considered a particular concern.
AI agents and software supply chains
Mandiant's 2026 AI Risk and Resilience report describes a shift from attackers using chatbots for research toward the use of autonomous agents during intrusion activity. The report cited examples involving a compromised coding assistant and the use of a language model to help troubleshoot data-exfiltration tooling after CI/CD credentials were stolen. It also highlighted operational risks from poorly controlled agents, including a case in which an accounting agent entered a costly reasoning loop.
CrowdStrike reported that an npm-based information stealer called PhantomRaven was distributed through typosquatted packages. The malware collects host information and CI/CD environment variables from services including GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike assessed that the author may also participate in bug bounty programs and may use stolen data to identify affected organizations rather than selling it through criminal forums.
Other patches and guidance
- Defiant said attackers have attempted to exploit a critical upload flaw in the WooCommerce Wholesale Lead Capture plugin to place PHP webshells on WordPress sites. Administrators should update to version 2.0.3.2 and review upload directories for suspicious files.
- TP-Link released firmware updates for two Tapo C200 camera issues, including an authentication bypass and a denial-of-service vulnerability.
- NIST and CISA issued final guidance on protecting signed tokens and identity assertions used in cloud single sign-on, federation, and API access systems.
