In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.

23 Million User Records Compromised in Gyazo Data Breach 

23 Million User Records Compromised in Gyazo Data Breach 

Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach  appeared first on SecurityWeek.

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.

NightmareStresser DDoS Service Disrupted in International Operation

NightmareStresser DDoS Service Disrupted in International Operation

Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.