Abuse of alternative runtime environments Deno-tes defender headaches
2026-08-12T20:51:32Z•adcfc57d78f2a8485f194b203f7af6db78d4448f0a8e65ed75ebd35155b023f4
CVE-2026-18577AI securityClickFixDFIR toolsDeno runtime abuseGOLD EMBRACEInterlock ransomwareN-able N-centralRMM deploymentcompromised WordPressdouble extortionfileless executioninfostealerliving-off-the-landnetwork tunnelingpersistent remote access
What happened
Sophos reporting highlights active threats involving abuse of the Deno runtime for fileless execution and infostealer delivery, ClickFix social-engineering campaigns, Interlock/GOLD EMBRACE ransomware activity, and exploitation of N-able N-central via CVE-2026-18577 to deploy RMM tools and network tunnels for persistent remote access. The feed also includes AI security and defensive product updates.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- adcfc57d78f2a8485f194b203f7af6db78d4448f0a8e65ed75ebd35155b023f4
- Enrichment time
- 2026-08-12T20:51:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.