www.securityweek.com 18 Sept 2026, 14:25 UTC

Ukrainian Ransomware Developer Gets 13 Years Over $123m Attacks

Ukrainian Ransomware Developer Gets 13 Years Over $123m Attacks
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown
Threat Actor
LockBit

SECURITYWEEK’S roundup reports that a Zurich court sentenced a Ukrainian IT specialist to nearly 13 years in prison for developing ransomware used in extortion attacks against companies including Stadler Rail. The court identified him as the lead developer behind the Lockergoga, MegaCortex and Nefilim ransomware families, while describing his role as closer to a technical consultant than the operation’s mastermind. Prosecutors estimated campaign-related damages at roughly $123 million. The verdict remains subject to appeal.

The roundup also highlights several vulnerability developments. SAP users were warned about CVE-2026-44756, a maximum-severity flaw in Extended Passport processing that allows unauthenticated memory corruption before login. Researchers said remote code execution was achievable in laboratory testing over HTTP/HTTPS and NGRFC, affecting products including S/4HANA, NetWeaver and Business Suite; SAP urged emergency patching of internet-facing systems.

Separately, researchers disclosed Plugin4Shell, a zero-click supply-chain flaw affecting Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. An attacker controlling a plugin repository could replace a reviewed, SHA-pinned commit with malicious code by exploiting how branches and commits are resolved, while automatic updates could deliver it without user action. Anthropic and OpenAI have issued fixes for Claude Code and Codex. Microsoft had not patched Copilot, and Google said its deprecated Gemini CLI would not be fixed.

Defiant reported more than 100,000 exploit attempts against a critical file-upload flaw in WooCommerce Wholesale Lead Capture. Unauthenticated attackers can upload PHP webshells by bypassing file-type checks; site owners should update to version 2.0.3.2 and inspect uploads for suspicious PHP files.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline