In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Summary
This cybersecurity news roundup covers several AI and security developments, including the sentencing of a ransomware developer to 13 years in prison, attacks where autonomous agents (AI systems that can act independently) are being used to conduct entire intrusions, and a JavaScript malware assessed to have been written by an LLM (large language model, an AI trained on text) that steals credentials from development tools. The week also highlights new guidance from NIST and CISA on protecting authentication tokens (digital credentials that verify identity) in cloud systems.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/
First tracked: September 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 75%