September 13, 2026
Why this day matters
- Explore this source record from Anthropic. Follow the canonical source link to read the original publication.
- CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · securityaffairsConti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
A U.S. federal court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison for conspiracy to commit wire fraud tied to deploying Conti ransomware.
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
A U.S. federal court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison for conspiracy to commit wire fraud tied to deploying Conti ransomware.
Source published Sep 13, 2026, 9:19 AM UTC · Evidence retrieved Sep 13, 2026, 2:51 PM UTC
What happened
A U.S. federal court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison for conspiracy to commit wire fraud tied to deploying Conti ransomware. [1] [2] [3] [4]
Conti attacks affected computers and networks in 47 U.S. states, 31 foreign countries, the District of Columbia, and Puerto Rico from 2020 through 2022; the FBI estimated associated victim payouts exceeded $150 million by January 2022. [5] [6]
Lytvynenko was assigned to code a loader used to load programs needed for other malicious attacks, and prosecutors linked his actions to at least 12 companies. [7] [8] [9]
Evidence from Lytvynenko’s accounts showed he possessed stolen data from eight U.S. victims and four overseas victims; he admitted joining a Conti team around September 2021 and holding stolen victim data. [10] [11] [12] [13] [14]
Lytvynenko pleaded guilty in June to a single count of wire fraud conspiracy; the charge carried a statutory maximum of 20 years, while the sentence imposed was four years. [19] [20] [21]
Why it matters
Forensic artifacts recovered during his July 2023 arrest in County Cork, Ireland, demonstrated ongoing involvement in ransomware activity after Conti’s 2022 shutdown. [15] [16] [17] [18] [19]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S.
- [2]
prison for ransomware attacks.
- [3]
A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy to commit wire fraud, the Justice Department announced, tied to his role in Conti , the ransomware operation blamed for infecting over 1,000 organizations worldwide.
- [4]
“Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide.” reads the announcement by DoJ.
- [5]
From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico.
- [6]
The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000.” Conti’s numbers put it in a different league from most ransomware groups that end up in a US courtroom.
- [7]
Prosecutors linked his actions to attacks on at least 12 companies, showing he played an active role rather than working on the sidelines.
- [8]
Specifically, he was assigned to code a “loader,” the kind of malware that opens the door for other malicious software to run once a machine is already compromised.
- [9]
Lytvynenko further admitted to joining a team run by a Conti conspirator during which time Lytvynenko was directed to work on coding a “loader,” which is typically a type of malware, or malicious software, that is used to load programs necessary to execute other malicious attacks.” DoJ continues.
- [10]
Investigators found stolen data from eight US victims and four overseas organizations in his accounts.
- [11]
Lytvynenko admitted to joining the group around September 2021.
- [12]
He acknowledged holding stolen data from multiple victims in the U.S.
- [13]
Evidence recovered from Lytvynenko’s online accounts showed he possessed data stolen from eight U.S.
- [14]
victims and four overseas victims.
- [15]
The most striking detail in this case is what happened after Conti supposedly stopped existing.
- [16]
The gang shut down its operation in 2022 after its internal chat logs and source code leaked publicly, following the group’s public declaration of support for Russia’s invasion of Ukraine, a leak that exposed the entire operation to researchers and law enforcement simultaneously.
- [17]
When Irish police showed up at his home in County Cork in July 2023, they reportedly found his laptop still open, running Cobalt Strike, with an active Rocket.
- [18]
Forensic evidence from that arrest demonstrated his ransomware activity had continued well past Conti’s collapse.
- [19]
“Forensic artifacts recovered at the time of his arrest in July 2023 in County Cork, Ireland, further demonstrated ongoing involvement in ransomware activity.” Lytvynenko pleaded guilty in June to a single count of wire fraud conspiracy, a charge that carried a statutory maximum of 20 years, making the four-year sentence a fraction of what he legally could have received.
- [20]
Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation.
- [21]
“Lytvynenko pleaded guilty to wire fraud conspiracy on June 10.
Luna-enriched source article · the hacker newsAttackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft disclosed two campaigns involving abuse of third-party email delivery infrastructure to send financial-fraud scam messages and passkey-themed social engineering to breach cloud environments.
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft disclosed two campaigns involving abuse of third-party email delivery infrastructure to send financial-fraud scam messages and passkey-themed social engineering to breach cloud environments.
Source published Sep 13, 2026, 10:11 AM UTC · Evidence retrieved Sep 13, 2026, 1:23 PM UTC
What happened
Microsoft disclosed two campaigns involving abuse of third-party email delivery infrastructure to send financial-fraud scam messages and passkey-themed social engineering to breach cloud environments. [1]
Microsoft said the first campaign sent more than one million scam emails between August 3 and 5, 2026, while masquerading as chief executive officers. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.
- [2]
The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
Additional source records
Material developmentsroadmap — Anthropic
Anthropic published a source item for review.
roadmap — Anthropic
Anthropic published a source item for review.
What happened
Anthropic published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- roadmap — Anthropic Anthropic · Published 2026-09-13T15:58:02Z · Retrieved Sep 13, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsGitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Securityaffairs published details for CVE-2026-85706.
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours
Securityaffairs published details for CVE-2026-85706.
What happened
Securityaffairs published details for CVE-2026-85706.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-85706.
Evidence
- GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours Securityaffairs · Published 2026-09-13T12:26:54Z · Retrieved Sep 13, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityWeek in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Helpnetsecurity published a source item for review.
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited Helpnetsecurity · Published 2026-09-13T08:00:57Z · Retrieved Sep 13, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.