In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
This security news roundup highlights multiple cybersecurity developments including a critical SAP vulnerability (CVE-2026-44756) allowing unauthenticated memory corruption, a WordPress plugin file-upload flaw enabling mass webshell uploads, and a zero-click Plugin4Shell vulnerability affecting AI coding assistants that permits silent malicious plugin updates. Additionally, it covers the sentencing of a ransomware developer, new malware linked to bug bounty hunting, and other notable cybercrime and defense updates.
AI Analysis
Technical Summary
The report covers several distinct cybersecurity issues: CVE-2026-44756 is a critical SAP Extended Passport processing flaw that allows unauthenticated attackers to cause memory corruption prior to login checks, enabling remote code execution over HTTP/HTTPS and NGRFC. The WooCommerce Wholesale Lead Capture WordPress plugin contains a critical file-upload vulnerability that lets unauthenticated users bypass file-type restrictions and upload PHP webshells, leading to widespread exploitation. Plugin4Shell is a zero-click vulnerability impacting AI coding assistants (Claude Code, OpenAI Codex, GitHub Copilot, Gemini CLI) where attackers controlling plugin repositories can swap pinned commits for malicious code without detection, enabling silent malicious plugin updates. Fixes have been released for most affected AI agents except Microsoft Copilot and deprecated Gemini CLI. Other news includes the sentencing of a ransomware developer responsible for Lockergoga, MegaCortex, and Nefilim ransomware, and the discovery of PhantomRaven npm malware linked to a bug bounty hunter. The report also mentions new guidance from NIST and CISA on cloud token theft defenses and law enforcement actions against cybercrime groups.
Potential Impact
The SAP vulnerability (CVE-2026-44756) poses a critical risk as it allows unauthenticated remote attackers to execute arbitrary code on affected SAP systems, potentially compromising enterprise environments. The WordPress plugin flaw enables attackers to upload webshells, facilitating persistent unauthorized access and control over websites. Plugin4Shell's zero-click exploit can silently compromise AI coding assistants by pushing malicious plugin updates without user intervention, potentially leading to supply chain attacks in software development workflows. The ransomware developer's sentencing disrupts a major extortion campaign responsible for significant financial damages. The PhantomRaven malware's use by a bug bounty hunter indicates novel abuse of open-source ecosystems for information theft. Overall, these issues represent serious risks to enterprise, web, and AI development security.
Mitigation Recommendations
SAP has issued an emergency patch for CVE-2026-44756 and urges immediate updating of internet-facing SAP systems. WordPress site owners must update the WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 and audit for suspicious PHP files, especially in upload directories. AI coding assistant users should apply available patches from Anthropic and OpenAI for Claude Code and Codex; Microsoft Copilot remains unpatched and Gemini CLI is deprecated with no fix planned. Organizations should monitor vendor advisories for updates and apply patches promptly. No additional generic mitigations are recommended beyond these vendor-directed actions.
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Description
This security news roundup highlights multiple cybersecurity developments including a critical SAP vulnerability (CVE-2026-44756) allowing unauthenticated memory corruption, a WordPress plugin file-upload flaw enabling mass webshell uploads, and a zero-click Plugin4Shell vulnerability affecting AI coding assistants that permits silent malicious plugin updates. Additionally, it covers the sentencing of a ransomware developer, new malware linked to bug bounty hunting, and other notable cybercrime and defense updates.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The report covers several distinct cybersecurity issues: CVE-2026-44756 is a critical SAP Extended Passport processing flaw that allows unauthenticated attackers to cause memory corruption prior to login checks, enabling remote code execution over HTTP/HTTPS and NGRFC. The WooCommerce Wholesale Lead Capture WordPress plugin contains a critical file-upload vulnerability that lets unauthenticated users bypass file-type restrictions and upload PHP webshells, leading to widespread exploitation. Plugin4Shell is a zero-click vulnerability impacting AI coding assistants (Claude Code, OpenAI Codex, GitHub Copilot, Gemini CLI) where attackers controlling plugin repositories can swap pinned commits for malicious code without detection, enabling silent malicious plugin updates. Fixes have been released for most affected AI agents except Microsoft Copilot and deprecated Gemini CLI. Other news includes the sentencing of a ransomware developer responsible for Lockergoga, MegaCortex, and Nefilim ransomware, and the discovery of PhantomRaven npm malware linked to a bug bounty hunter. The report also mentions new guidance from NIST and CISA on cloud token theft defenses and law enforcement actions against cybercrime groups.
Potential Impact
The SAP vulnerability (CVE-2026-44756) poses a critical risk as it allows unauthenticated remote attackers to execute arbitrary code on affected SAP systems, potentially compromising enterprise environments. The WordPress plugin flaw enables attackers to upload webshells, facilitating persistent unauthorized access and control over websites. Plugin4Shell's zero-click exploit can silently compromise AI coding assistants by pushing malicious plugin updates without user intervention, potentially leading to supply chain attacks in software development workflows. The ransomware developer's sentencing disrupts a major extortion campaign responsible for significant financial damages. The PhantomRaven malware's use by a bug bounty hunter indicates novel abuse of open-source ecosystems for information theft. Overall, these issues represent serious risks to enterprise, web, and AI development security.
Defensive Guidance
SAP has issued an emergency patch for CVE-2026-44756 and urges immediate updating of internet-facing SAP systems. WordPress site owners must update the WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 and audit for suspicious PHP files, especially in upload directories. AI coding assistant users should apply available patches from Anthropic and OpenAI for Claude Code and Codex; Microsoft Copilot remains unpatched and Gemini CLI is deprecated with no fix planned. Organizations should monitor vendor advisories for updates and apply patches promptly. No additional generic mitigations are recommended beyond these vendor-directed actions.
Technical Details
- Classification
- {"confidence":0.79,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/","fetched":true,"fetchedAt":"2026-09-18T14:31:43.002Z","wordCount":1641}
Threat ID: 6aad4b4f55bf5e2cf51f5816
Added to database: 09/18/2026, 14:31:43 UTC
Last enriched: 09/18/2026, 14:31:49 UTC
Last updated: 09/19/2026, 03:49:02 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.