In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

Here are this week’s highlights: 

Raindrop raises $35 million for AI agent monitoring

Raindrop, designed to detect unknown failures in autonomous agents, announced a Series A funding round of $35 million, adding to last year’s $15 million seed round. Raindrop continuously analyzes agent behavior to surface silent and emerging failure modes, and to help AI systems repair and learn from them.

Advertisement. Scroll to continue reading.

Mandiant’s 2026 AI risk report highlights agentic attack escalation

Mandiant’s latest AI Risk and Resilience report finds that attackers have moved from prompting AI chatbots for research to letting autonomous agents run entire intrusions, citing incidents where a hijacked coding assistant helped spread a self-propagating worm across roughly 100 repositories and a compromised CI/CD credential let an attacker co-debug exfiltration tools with an LLM in real time. Separately, the report flags a new financial risk category, detailing a case where a corrupted value sent an accounting agent into a runaway reasoning loop that racked up over 15,000 API calls and roughly $50,000 in cloud costs in under an hour. 

Npm info-stealer author cashes in on bug bounty programs

CrowdStrike has tied an npm-based information stealer called PhantomRaven to a financially motivated actor who moonlights as a bug bounty hunter. The JavaScript malware, distributed through typosquatted npm packages, is assessed with high confidence to have been written by an LLM based on its verbose comments and placeholder code, and it harvests system details plus CI/CD environment variables from GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike found no evidence the stolen data is sold on criminal marketplaces, suggesting the operator uses it purely to flag compromises for bounty payouts.

Black Axe leaders extradited to US over cybercrime network

Five leaders of the Cape Town chapter of Nigeria’s Black Axe crime syndicate have been extradited from South Africa to New Jersey to face wire fraud and money laundering conspiracy charges. Prosecutors say the group ran romance scams and advance-fee schemes against US victims from 2011 to 2021. The defendants, arrested in South Africa in 2021, also face related wire fraud and identity theft counts tied to business email compromise.

Ransomware developer gets 13-year prison sentence in Switzerland

A Zurich court sentenced a Ukrainian IT specialist to nearly 13 years in prison for developing ransomware used in extortion attacks on companies including Stadler Rail. The court identified him as the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware families, though it described his role as closer to a technical consultant than the operation’s mastermind. Prosecutors estimated total damages from the campaign at roughly $123 million, and the verdict remains subject to appeal.

NIST, CISA detail defenses against token theft in the cloud

NIST and CISA have published a final joint report giving federal agencies and cloud providers implementation guidance for protecting the signed tokens and identity assertions that underpin single sign-on, federation, and API access. The report addresses token validation, secrets management, and detection at scale, incorporating feedback gathered through CISA’s Joint Cyber Defense Collaborative on an earlier draft. It builds on NIST’s existing security and privacy controls guidance and supports Secure by Design principles.

Organizations warned of critical SAP vulnerability

Organizations using SAP have been warned about CVE-2026-44756, a maximum-severity flaw in its Extended Passport processing code that lets unauthenticated attackers trigger memory corruption before any login check occurs. Onapsis discovered the vulnerability and dubbed it OVERPASS. Researchers from Pathlock and nullFaktor confirmed remote code execution is achievable over HTTP/HTTPS and NGRFC in lab testing, and warned that public technical write-ups released within 48 hours of the patch lower the bar for exploit development. The bug touches a wide range of SAP products, including S/4HANA, NetWeaver, and Business Suite. SAP is urging emergency patching of internet-facing systems.

WordPress plugin bug fuels mass webshell uploads

Defiant says attackers have exploited a critical file-upload flaw in the WooCommerce Wholesale Lead Capture plugin, blocking more than 100,000 exploit attempts since the bug was disclosed in February. The flaw lets unauthenticated visitors bypass file-type checks and upload PHP webshells because the plugin trusts an attacker-supplied list of allowed extensions instead of its own configuration. Site owners are urged to update to version 2.0.3.2 and check for suspicious PHP files, particularly in the uploads directory.

TP-Link patches Tapo camera flaw that skips password checks

OPSWAT researchers found two flaws in TP-Link’s Tapo C200 security camera, including an authentication bypass that lets an attacker on the network replay a value from the camera’s own challenge-response process to gain admin access without a password. A second bug allows a denial-of-service attack by sending oversized Wi-Fi credential data during device onboarding, crashing the camera’s HTTPS service. TP-Link fixed both issues, tracked as CVE-2026-15315 and CVE-2026-15316, in firmware V5_1.4.6 released in August.

Plugin auto-updates open door to silent AI agent takeover

Researchers at Air’s security lab disclosed Plugin4Shell, a zero-click flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI that lets an attacker controlling a plugin’s repository swap a pinned, reviewed commit for malicious code without tripping the SHA-pinning check. Because the affected agents check out a requested commit without verifying what actually landed, an attacker can name a branch after the pinned hash so git resolves to it instead, and background auto-updates push the malicious version to already-installed plugins with no user action. Anthropic and OpenAI have shipped fixes for Claude Code and Codex, Microsoft has not yet patched Copilot, and Google says the deprecated Gemini CLI will not be fixed at all.

Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/




Researchers used Claude to hack OpenAI

Cyber researchers broke into OpenAI using its key rival Anthropic’s software, highlighting vulnerabilities in the ChatGPT maker’s security as leading AI companies face mounting scrutiny over safety.

A small cyber security group gained access to an OpenAI employee’s ChatGPT account, which permitted them to read private software information and suggest changes.

The researchers had been given access to an Anthropic tool specifically designed for security professionals, and were paid for the work as part of a program to find vulnerabilities before they could be exploited by bad actors.

Read full article

Comments

https://arstechnica.com/ai/2026/09/researchers-used-claude-to-hack-openai/




AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI’s sign-in system to take over employee ChatGPT and Codex accounts, and ultimately gained access to internal code repositories.

The entry point was OpenAI’s community forum, community.openai.com, which runs on Discourse. Discourse’s built-in image checks didn’t support the HEIC/HEIF photo format, so uploads in that format were passed to ImageMagick, exposing an unpatched flaw in the libheif library it relies on for decoding. 

Hacktron says the underlying bug had been fixed upstream a year earlier without ever being flagged as a security issue, so it was never assigned a CVE and missed the usual patching cycle.

Turning the flaw into a reliable exploit took several attempts and involved Claude Opus 4.8 and Opus 5. The exploit allowed remote code execution, which the researchers first used against a test Discourse instance, then on OpenAI’s own forum.

Because the forum let people sign in with their OpenAI account, code execution there opened a path to broader account access. Hacktron says that until the issue was fixed, any user or employee who logged into the forum could have had their ChatGPT and Codex accounts taken over.

In addition, since people often connect other services to those accounts, the theoretical exposure extended to services like GitHub, Slack and email.

Advertisement. Scroll to continue reading.

OpenAI distinguishes between the two flaws. It told SecurityWeek that the image-processing bug lived in the third-party service Discourse, while the account-takeover path was a separate, OpenAI-side issue. 

The OpenAI weakness was related to sign-in tokens generated for the community forum carrying excessive permissions and granting full API access to associated ChatGPT and Codex accounts.

To demonstrate the access without reading any internal code, Hacktron says it took over an OpenAI employee’s account whose Codex integration was linked to OpenAI’s GitHub organization, then used it to open a pull request in an internal repository before stopping further testing. 

OpenAI said its own review of the incident found limited reads of private-repository metadata and commits, followed by the researcher-submitted pull request, specifically to a README file.

Hacktron’s report also raises Slack as a service that could theoretically have been reached through connected accounts. OpenAI says Hacktron did not verify actual access to employee Slack messages.

The security firm reported the account-takeover issue to OpenAI through Bugcrowd, and the AI giant confirmed a fix about 14 hours later. It separately reported the libheif flaw to Discourse through HackerOne. Discourse had a fix ready within two days and added image-processing sandboxing as an extra layer of defense, then published a security advisory.

In a statement, OpenAI said, “We thank the researchers for contacting us and sharing their findings. We narrowed the permissions on Community sign-in tokens and revoked affected tokens and sessions.” 

The company paid Hacktron a $6,500 bounty for the OpenAI-side finding. 

Related: OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Related: AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

Related: OpenAI Investigates Report Linking AI Agents to RubyGems Attack

https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/




Beyond Hollywood: Atlanta’s New Entertainment Economy

Atlanta is rapidly emerging as one of America’s most influential entertainment and creative hubs. The city is creating new opportunities for brands willing to rethink how they approach storytelling and partnerships. 

On Adspeak by ADWEEK, host Bashel Lewis moderates a Brandweek panel with three media and creative leaders: Blondel Aidoo, co-founder at Rabbit Hole Technologies; Eddy Moretti, executive producer at Laugh Cry Wow; and Asante Bradford, senior industry engagement manager at the Georgia Department of Economic Development.

Together, they explore how Atlanta is evolving from a production destination into a sustainable creative powerhouse with a thriving talent ecosystem, production infrastructure, and attractive incentives. 

The conversation examines how brands can build authentic partnerships with creators, production companies, sports franchises, and music properties while moving beyond traditional studio models. 

They also discuss the growing importance of emerging talent, HBCUs, and local creative pipelines, and the democratization of storytelling. 

For brands looking to invest in culture, entertainment, and next-generation content, Atlanta offers an increasingly compelling opportunity to build meaningful partnerships and connect with audiences in new ways. 

[embedded content]

What you’ll learn:

  • Why Atlanta Offers a Competitive Edge Over Traditional Production Hubs
  • Building Relationships with Atlanta-Based Creators and Production Companies
  • Why The Brand Partnership Model is Replacing Traditional Studio Financing
  • How to Tap into HBCUs and Local Talent Pipelines for Long-Term Brand Building
  • The Democratization of Content Creation Means Story Quality Matters More 
  • Why Sports, Music, and True Crime Content Create Immediate Brand Partnership Opportunities

About the guests:

Blondel Aidoo is co-founder of Rabbit Hole Technologies, a next-generation animation studio blending art, AI, and innovation to transform storytelling. With 35+ years of experience as a visual effects producer, his credits include Minority Report, X-Men, Spider-Man, Night at the Museum, and Red Notice, films that have collectively grossed more than $8 billion worldwide. Blondel is building an AI-driven production ecosystem that helps filmmakers and brands create, iterate, and bring ambitious stories to life faster.

Award-winning producer and creative director Eddy Moretti is the executive producer at Laugh Cry Wow and has developed and produced more than 200 films and television series, alongside thousands of hours of cable and digital content. Previously chief creative officer at Vice Media for two decades, he led content across its flagship properties and branded partnerships. Moretti also launched Viceland, an award-winning global cable channel, and his work has earned multiple Emmys, Peabody Awards, Cannes Lions, and other honors.

Asante Bradford is the senior industry engagement manager at the Georgia Department of Economic Development, where he helps strengthen Georgia’s position as a leader in creative technology and innovation. With experience spanning entertainment, education, and government, he builds strategic partnerships and drives initiatives across gaming, film, and interactive media. Asante has helped attract high-impact projects to the state and serves as a trusted resource on Georgia’s entertainment incentives and the growth of its creative economy.

https://www.adweek.com/brand-marketing/beyond-hollywood-atlantas-new-entertainment-economy/




Why AI Can Never Replace Great Agencies ft. Andy Lopez, CMO of Behr Paint

Plus, why consumer confidence matters as much as consumer inspiration. https://www.adweek.com/brand-marketing/why-ai-can-never-replace-great-agencies-ft-andy-lopez-cmo-of-behr-paint/




23 Million User Records Compromised in Gyazo Data Breach 

Japanese software company Helpfeel is notifying users of its Gyazo image-sharing service that hackers have accessed their information.

Gyazo is a widely used cross-platform tool that lets users capture screenshots, GIFs, or short screen recordings and instantly generate shareable links.

Helpfeel revealed this week that it recently detected unauthorized access to Gyazo servers. A hacker exploited a vulnerability in its image upload server on September 11, enabling them to execute malicious commands. 

The attacker was kicked out the next day, but not before accessing a database storing roughly 23.6 million user records.

The compromised Gyazo user information includes names, email addresses, password hashes, user and device IDs, X integration tokens, profile information, usage statistics, and billing information.

Payment card information was not compromised, according to the vendor.

Advertisement. Scroll to continue reading.

“The approximately 23.62 million affected records include records for anonymous accounts with no registered email address or similar information. We are continuing to determine the actual number of individuals whose personal information was disclosed without authorization,” Helpfeel said. 

In addition to the user records, the attacker accessed roughly 490 million image metadata records. This metadata includes information that could allow threat actors to reconstruct and access URLs associated with images uploaded by users. 

A list of private images has also been compromised, but the company has not shared any information on volume. 

Related: Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Related: Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Related: 280,000 Impacted by Premier Medical Group Data Breach

https://www.securityweek.com/23-million-user-records-compromised-in-gyazo-data-breach/




Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products. 

Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. 

Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal.

Microsoft rated all vulnerabilities as critical, but their CVSS scores indicate high or medium severity for some.

While some of these flaws were discovered internally by Microsoft, many were reported to the software giant by external researchers.

None of the vulnerabilities have been flagged as exploited, and Microsoft noted that all fixes were implemented on the server side, meaning that customers do not need to take any action.

Advertisement. Scroll to continue reading.

Microsoft also announced patches this week for a privilege escalation vulnerability affecting Windows. Users do need to update Windows to resolve this flaw, tracked as CVE-2026-85921, but Microsoft believes exploitation is ‘less likely’.

Like most major organizations, Microsoft has seen vulnerability discovery surge in recent months, driven by increased use of advanced AI. The company fixed a record-breaking 970 vulnerabilities across its products with the latest Patch Tuesday updates. 

Related: Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Related: Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/




Disney Continues Leadership Shifts With Streaming Shakeup

Disney names Adam Smith new DTC boss. https://www.adweek.com/convergent-tv/disney-continues-leadership-shifts-with-streaming-shakeup/




3 Ways Starbucks Is Reclaiming Its Brand Magic

The cafe chain’s brand chief Tressie Lieberman on rebuilding Starbucks through fandom, consistency, and participation. https://www.adweek.com/brand-marketing/3-ways-starbucks-is-reclaiming-its-brand-magic/




NightmareStresser DDoS Service Disrupted in International Operation

NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) for-hire services in the world, has been disrupted.

The US Department of Justice announced this week that the FBI has seized the internet domains associated with the booter service.

Visitors to nightmare-stresser[.]com and nightmarestresser[.]org are now served a seizure banner.

Authorities said NightmareStresser had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide.

However, security researcher Alex Carter reported last year that NightmareStresser was likely founded in 2016 and became popular in 2018, after rival services were disrupted, becoming the largest DDoS tool in 2019.

By 2025, it had grown to nearly 1 million users. It could launch between 3,000 and 4,000 attacks per hour, accepted cryptocurrency payments, but avoided government, education, and hospital domains.

Advertisement. Scroll to continue reading.

The NightmareStresser takedown was part of Operation PowerOFF, a coordinated global effort to dismantle DDoS-for-hire infrastructures globally and hold the individuals behind these services accountable.

DDoS-for-hire services, also referred to as booters or stressers, have been proliferating over the past years, as they represent low-entry barriers for cybercriminal-wannabes, the DoJ notes.

Over the past eight years, the US charged 12 DDoS attack facilitators and seized over 100 domains associated with booter services.

In April, law enforcement agencies in 21 countries disrupted 53 domains associated with DDoS-for-hire services. Last year, the US disrupted the RapperBot DDoS botnet, and 27 websites linked to booter services were seized in 2024.

In addition to disrupting DDoS-for-hire infrastructure, law enforcement agencies have been tracking and charging both the administrators and the users of these services.

Related: 23-Year-Old Sality P2P Botnet Disrupted

Related: US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

Related: Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices

Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/