Threat Research
AI
malvertising
infostealer
Sophos X-Ops
A year of MDR casework shows attackers repeatedly exploiting demand for AI tools
clickfix
Deno
WordPress
Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealer
Attack TTPs combine fileless execution, wide LOLBin use
RMM
N-able
vulnerability
After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access