Gbhackers CastleRAT Exploits Deno Runtime to Evade Security Measures
Article Content
- •CastleRAT uses the Deno JavaScript runtime to bypass security measures.
- •The attack targets organizations utilizing Deno for application development.
- •No specific CVEs have been disclosed yet, but IOCs are available.
A new cyberattack known as CastleRAT has emerged, utilizing the Deno JavaScript runtime to bypass enterprise security defenses. The attack primarily targets organizations using Deno for application development, potentially affecting thousands of systems globally. CastleRAT employs sophisticated techniques to evade detection, making it a significant threat to enterprise environments. Security researchers have identified multiple indicators of compromise (IOCs) associated with this attack, although specific CVEs have not yet been disclosed. The scope of the impact remains under investigation, with reports of compromised systems increasing. Organizations are urged to review their security configurations and monitor for unusual activity. As of now, no official patch or remediation guidance has been released. The situation is evolving, and further updates are expected as more information becomes available.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (1)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…