Swiss Court Sentences Ransomware Developer and Plugin4Shell Flaw Disclosed
At a glance
- Zurich District Court sentenced a Ukrainian national for ransomware development.
- Plugin4Shell vulnerability affecting AI coding agents was disclosed.
- Patches released for Claude Code and OpenAI Codex; others unpatched or deprecated.
Recent security incidents include a court sentencing related to ransomware and the public disclosure of a critical vulnerability affecting several AI coding tools. Both events highlight ongoing risks in cybersecurity and software supply chains.
The Zurich District Court sentenced a 52-year-old Ukrainian national to 12 years and nine months in prison for developing the LockerGoga, MegaCortex, and Nefilim ransomware. The court also imposed a ten-year ban from Switzerland as part of the ruling.
Separately, Air Security disclosed the Plugin4Shell vulnerability on September 18, 2026. This flaw allows remote code execution without user interaction and affects multiple AI coding agents, including Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI, through a SHA-pinning bypass.
Anthropic addressed the Plugin4Shell issue in Claude Code by releasing version 2.1.179, while OpenAI released a patch for Codex in version 0.146.0. At the time of disclosure, GitHub Copilot and Gemini CLI remained either unpatched or had been deprecated.
What the numbers show
- 12 years and 9 months: prison sentence issued by Zurich District Court.
- September 18, 2026: Plugin4Shell vulnerability disclosure date.
- Claude Code patched in version 2.1.179; Codex patched in version 0.146.0.
The Plugin4Shell vulnerability was identified as a zero-click remote code execution flaw. According to Air Security, the flaw exploited a SHA-pinning bypass, which allowed attackers to compromise affected AI coding agents without user intervention.
Claude Code and OpenAI Codex received updates to address the vulnerability, while GitHub Copilot and Gemini CLI did not have patches available at the time of the disclosure. The lack of updates for some tools left certain users without immediate remediation options.
The sentencing in Zurich and the vulnerability disclosure occurred within days of each other, drawing attention to both law enforcement actions against cybercrime and ongoing technical challenges in software security.
Both incidents were confirmed by official sources, with the court ruling reported by the Zurich District Court and the vulnerability details published by Air Security through Cloud Security Alliance Labs.
* This article is based on publicly available information at the time of writing.