• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

In Different Information: Ransomware Developer Sentenced, Plugin4Shell AI Assault, Important SAP Flaw

Admin by Admin
September 19, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


SecurityWeek’s weekly cybersecurity information roundup affords a concise overview of essential developments that will not obtain full standalone protection but stay related to the broader menace panorama.

This curated abstract highlights key tales throughout vulnerability disclosures, rising assault strategies, coverage updates, trade reviews, and different noteworthy occasions to assist readers keep well-informed in regards to the evolving cybersecurity setting.

Listed here are this week’s highlights: 

Raindrop raises $35 million for AI agent monitoring

Raindrop, designed to detect unknown failures in autonomous brokers, introduced a Collection A funding spherical of $35 million, including to final yr’s $15 million seed spherical. Raindrop constantly analyzes agent conduct to floor silent and rising failure modes, and to assist AI techniques restore and study from them.

Commercial. Scroll to proceed studying.

Mandiant’s 2026 AI threat report highlights agentic assault escalation

Mandiant’s newest AI Threat and Resilience report finds that attackers have moved from prompting AI chatbots for analysis to letting autonomous brokers run complete intrusions, citing incidents the place a hijacked coding assistant helped unfold a self-propagating worm throughout roughly 100 repositories and a compromised CI/CD credential let an attacker co-debug exfiltration instruments with an LLM in actual time. Individually, the report flags a brand new monetary threat class, detailing a case the place a corrupted worth despatched an accounting agent right into a runaway reasoning loop that racked up over 15,000 API calls and roughly $50,000 in cloud prices in below an hour. 

Npm info-stealer writer cashes in on bug bounty packages

CrowdStrike has tied an npm-based data stealer known as PhantomRaven to a financially motivated actor who moonlights as a bug bounty hunter. The JavaScript malware, distributed via typosquatted npm packages, is assessed with excessive confidence to have been written by an LLM primarily based on its verbose feedback and placeholder code, and it harvests system particulars plus CI/CD setting variables from GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike discovered no proof the stolen information is offered on felony marketplaces, suggesting the operator makes use of it purely to flag compromises for bounty payouts.

Black Axe leaders extradited to US over cybercrime community

5 leaders of the Cape City chapter of Nigeria’s Black Axe crime syndicate have been extradited from South Africa to New Jersey to face wire fraud and cash laundering conspiracy expenses. Prosecutors say the group ran romance scams and advance-fee schemes towards US victims from 2011 to 2021. The defendants, arrested in South Africa in 2021, additionally face associated wire fraud and id theft counts tied to enterprise e mail compromise.

Ransomware developer will get 13-year jail sentence in Switzerland

A Zurich court docket sentenced a Ukrainian IT specialist to just about 13 years in jail for creating ransomware utilized in extortion assaults on firms together with Stadler Rail. The court docket recognized him because the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware households, although it described his position as nearer to a technical advisor than the operation’s mastermind. Prosecutors estimated complete damages from the marketing campaign at roughly $123 million, and the decision stays topic to attraction.

NIST, CISA element defenses towards token theft within the cloud

NIST and CISA have revealed a remaining joint report giving federal businesses and cloud suppliers implementation steering for safeguarding the signed tokens and id assertions that underpin single sign-on, federation, and API entry. The report addresses token validation, secrets and techniques administration, and detection at scale, incorporating suggestions gathered via CISA’s Joint Cyber Protection Collaborative on an earlier draft. It builds on NIST’s present safety and privateness controls steering and helps Safe by Design ideas.

Organizations warned of vital SAP vulnerability

Organizations utilizing SAP have been warned about CVE-2026-44756, a maximum-severity flaw in its Prolonged Passport processing code that lets unauthenticated attackers set off reminiscence corruption earlier than any login test happens. Onapsis found the vulnerability and dubbed it OVERPASS. Researchers from Pathlock and nullFaktor confirmed distant code execution is achievable over HTTP/HTTPS and NGRFC in lab testing, and warned that public technical write-ups launched inside 48 hours of the patch decrease the bar for exploit growth. The bug touches a variety of SAP merchandise, together with S/4HANA, NetWeaver, and Enterprise Suite. SAP is urging emergency patching of internet-facing techniques.

WordPress plugin bug fuels mass webshell uploads

Defiant says attackers have exploited a vital file-upload flaw within the WooCommerce Wholesale Lead Seize plugin, blocking greater than 100,000 exploit makes an attempt because the bug was disclosed in February. The flaw lets unauthenticated guests bypass file-type checks and add PHP webshells as a result of the plugin trusts an attacker-supplied listing of allowed extensions as a substitute of its personal configuration. Website homeowners are urged to replace to model 2.0.3.2 and test for suspicious PHP information, significantly within the uploads listing.

TP-Hyperlink patches Tapo digicam flaw that skips password checks

OPSWAT researchers discovered two flaws in TP-Hyperlink’s Tapo C200 safety digicam, together with an authentication bypass that lets an attacker on the community replay a worth from the digicam’s personal challenge-response course of to realize admin entry with out a password. A second bug permits a denial-of-service assault by sending outsized Wi-Fi credential information throughout system onboarding, crashing the digicam’s HTTPS service. TP-Hyperlink mounted each points, tracked as CVE-2026-15315 and CVE-2026-15316, in firmware V5_1.4.6 launched in August.

Plugin auto-updates open door to silent AI agent takeover

Researchers at Air’s safety lab disclosed Plugin4Shell, a zero-click flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI that lets an attacker controlling a plugin’s repository swap a pinned, reviewed commit for malicious code with out tripping the SHA-pinning test. As a result of the affected brokers take a look at a requested commit with out verifying what truly landed, an attacker can identify a department after the pinned hash so git resolves to it as a substitute, and background auto-updates push the malicious model to already-installed plugins with no person motion. Anthropic and OpenAI have shipped fixes for Claude Code and Codex, Microsoft has not but patched Copilot, and Google says the deprecated Gemini CLI is not going to be mounted in any respect.

Associated: In Different Information: InjectEave Assault, SIM Swapper Sentenced, Glasswing Findings Evaluation

Associated: In Different Information: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Tags: AttackCriticalDeveloperFlawNewsPlugin4ShellRansomwareSAPSentenced
Admin

Admin

Next Post
Invoice Skarsgård Sounds Very Excited To Be Starring In Hideo Kojima’s Physint

Invoice Skarsgård Sounds Very Excited To Be Starring In Hideo Kojima's Physint

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Vampire Survivors Studio Suggests It Could Scrap Fortnite Crossover After Epic Video games Confirms Generative AI Utilization

Vampire Survivors Studio Suggests It Could Scrap Fortnite Crossover After Epic Video games Confirms Generative AI Utilization

June 18, 2026
NVIDIA Introduces CLIMB: A Framework for Iterative Information Combination Optimization in Language Mannequin Pretraining

NVIDIA Introduces CLIMB: A Framework for Iterative Information Combination Optimization in Language Mannequin Pretraining

April 19, 2025

Trending.

AI & data-driven Starbucks – Deep Brew

AI & data-driven Starbucks – Deep Brew

May 18, 2026
Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

Meet FreeToken: An Edge-Native MoE Serving Engine that Runs 753B GLM-5.2 on a Single Workstation GPU

August 23, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

August 29, 2026
Hasbro Information Breach Uncovered Worker Private Data

Hasbro Information Breach Uncovered Worker Private Data

August 30, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Not all AI staff assume the tech might kill everybody

Not all AI staff assume the tech might kill everybody

September 20, 2026
Claude Opus 5 Helped Researchers Take Over OpenAI Employees Accounts by way of Chained Flaws

Claude Opus 5 Helped Researchers Take Over OpenAI Employees Accounts by way of Chained Flaws

September 20, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved