Abuse of alternative runtime environments Deno-tes defender headaches

2026-08-12T20:51:32Zadcfc57d78f2a8485f194b203f7af6db78d4448f0a8e65ed75ebd35155b023f4
CVE-2026-18577AI securityClickFixDFIR toolsDeno runtime abuseGOLD EMBRACEInterlock ransomwareN-able N-centralRMM deploymentcompromised WordPressdouble extortionfileless executioninfostealerliving-off-the-landnetwork tunnelingpersistent remote access

What happened

Sophos reporting highlights active threats involving abuse of the Deno runtime for fileless execution and infostealer delivery, ClickFix social-engineering campaigns, Interlock/GOLD EMBRACE ransomware activity, and exploitation of N-able N-central via CVE-2026-18577 to deploy RMM tools and network tunnels for persistent remote access. The feed also includes AI security and defensive product updates.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
adcfc57d78f2a8485f194b203f7af6db78d4448f0a8e65ed75ebd35155b023f4
Enrichment time
2026-08-12T20:51:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Abuse of alternative runtime environments Deno-tes defender headaches · Baitaphish