SECURITYWEEK’S roundup reports that a Zurich court sentenced a Ukrainian IT specialist to nearly 13 years in prison for developing ransomware used in extortion attacks against companies including Stadler Rail. The court identified him as the lead developer behind the Lockergoga, MegaCortex and Nefilim ransomware families, while describing his role as closer to a technical consultant than the operation’s mastermind. Prosecutors estimated campaign-related damages at roughly $123 million. The verdict remains subject to appeal.
The roundup also highlights several vulnerability developments. SAP users were warned about CVE-2026-44756, a maximum-severity flaw in Extended Passport processing that allows unauthenticated memory corruption before login. Researchers said remote code execution was achievable in laboratory testing over HTTP/HTTPS and NGRFC, affecting products including S/4HANA, NetWeaver and Business Suite; SAP urged emergency patching of internet-facing systems.
Separately, researchers disclosed Plugin4Shell, a zero-click supply-chain flaw affecting Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. An attacker controlling a plugin repository could replace a reviewed, SHA-pinned commit with malicious code by exploiting how branches and commits are resolved, while automatic updates could deliver it without user action. Anthropic and OpenAI have issued fixes for Claude Code and Codex. Microsoft had not patched Copilot, and Google said its deprecated Gemini CLI would not be fixed.
Defiant reported more than 100,000 exploit attempts against a critical file-upload flaw in WooCommerce Wholesale Lead Capture. Unauthenticated attackers can upload PHP webshells by bypassing file-type checks; site owners should update to version 2.0.3.2 and inspect uploads for suspicious PHP files.