SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.
This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.
Here are this week’s highlights:
Raindrop raises $35 million for AI agent monitoring
Raindrop, designed to detect unknown failures in autonomous agents, announced a Series A funding round of $35 million, adding to last year’s $15 million seed round. Raindrop continuously analyzes agent behavior to surface silent and emerging failure modes, and to help AI systems repair and learn from them.
Mandiant’s 2026 AI risk report highlights agentic attack escalation
Mandiant’s latest AI Risk and Resilience report finds that attackers have moved from prompting AI chatbots for research to letting autonomous agents run entire intrusions, citing incidents where a hijacked coding assistant helped spread a self-propagating worm across roughly 100 repositories and a compromised CI/CD credential let an attacker co-debug exfiltration tools with an LLM in real time. Separately, the report flags a new financial risk category, detailing a case where a corrupted value sent an accounting agent into a runaway reasoning loop that racked up over 15,000 API calls and roughly $50,000 in cloud costs in under an hour.
Npm info-stealer author cashes in on bug bounty programs
CrowdStrike has tied an npm-based information stealer called PhantomRaven to a financially motivated actor who moonlights as a bug bounty hunter. The JavaScript malware, distributed through typosquatted npm packages, is assessed with high confidence to have been written by an LLM based on its verbose comments and placeholder code, and it harvests system details plus CI/CD environment variables from GitHub Actions, GitLab CI, Jenkins, and CircleCI. CrowdStrike found no evidence the stolen data is sold on criminal marketplaces, suggesting the operator uses it purely to flag compromises for bounty payouts.
Black Axe leaders extradited to US over cybercrime network
Five leaders of the Cape Town chapter of Nigeria’s Black Axe crime syndicate have been extradited from South Africa to New Jersey to face wire fraud and money laundering conspiracy charges. Prosecutors say the group ran romance scams and advance-fee schemes against US victims from 2011 to 2021. The defendants, arrested in South Africa in 2021, also face related wire fraud and identity theft counts tied to business email compromise.
Ransomware developer gets 13-year prison sentence in Switzerland
A Zurich court sentenced a Ukrainian IT specialist to nearly 13 years in prison for developing ransomware used in extortion attacks on companies including Stadler Rail. The court identified him as the lead developer behind the Lockergoga, MegaCortex, and Nefilim ransomware families, though it described his role as closer to a technical consultant than the operation’s mastermind. Prosecutors estimated total damages from the campaign at roughly $123 million, and the verdict remains subject to appeal.
NIST, CISA detail defenses against token theft in the cloud
NIST and CISA have published a final joint report giving federal agencies and cloud providers implementation guidance for protecting the signed tokens and identity assertions that underpin single sign-on, federation, and API access. The report addresses token validation, secrets management, and detection at scale, incorporating feedback gathered through CISA’s Joint Cyber Defense Collaborative on an earlier draft. It builds on NIST’s existing security and privacy controls guidance and supports Secure by Design principles.
Organizations warned of critical SAP vulnerability
Organizations using SAP have been warned about CVE-2026-44756, a maximum-severity flaw in its Extended Passport processing code that lets unauthenticated attackers trigger memory corruption before any login check occurs. Onapsis discovered the vulnerability and dubbed it OVERPASS. Researchers from Pathlock and nullFaktor confirmed remote code execution is achievable over HTTP/HTTPS and NGRFC in lab testing, and warned that public technical write-ups released within 48 hours of the patch lower the bar for exploit development. The bug touches a wide range of SAP products, including S/4HANA, NetWeaver, and Business Suite. SAP is urging emergency patching of internet-facing systems.
WordPress plugin bug fuels mass webshell uploads
Defiant says attackers have exploited a critical file-upload flaw in the WooCommerce Wholesale Lead Capture plugin, blocking more than 100,000 exploit attempts since the bug was disclosed in February. The flaw lets unauthenticated visitors bypass file-type checks and upload PHP webshells because the plugin trusts an attacker-supplied list of allowed extensions instead of its own configuration. Site owners are urged to update to version 2.0.3.2 and check for suspicious PHP files, particularly in the uploads directory.
TP-Link patches Tapo camera flaw that skips password checks
OPSWAT researchers found two flaws in TP-Link’s Tapo C200 security camera, including an authentication bypass that lets an attacker on the network replay a value from the camera’s own challenge-response process to gain admin access without a password. A second bug allows a denial-of-service attack by sending oversized Wi-Fi credential data during device onboarding, crashing the camera’s HTTPS service. TP-Link fixed both issues, tracked as CVE-2026-15315 and CVE-2026-15316, in firmware V5_1.4.6 released in August.
Plugin auto-updates open door to silent AI agent takeover
Researchers at Air’s security lab disclosed Plugin4Shell, a zero-click flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI that lets an attacker controlling a plugin’s repository swap a pinned, reviewed commit for malicious code without tripping the SHA-pinning check. Because the affected agents check out a requested commit without verifying what actually landed, an attacker can name a branch after the pinned hash so git resolves to it instead, and background auto-updates push the malicious version to already-installed plugins with no user action. Anthropic and OpenAI have shipped fixes for Claude Code and Codex, Microsoft has not yet patched Copilot, and Google says the deprecated Gemini CLI will not be fixed at all.
Related: In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
