Why Encrypted File Sharing Is Essential for Modern Businesses
2026-06-02T08:51:44Z•d864def91e696d412ec6f7634390143260924843bf40d78c67fdb18ca4064960
PureLogscredential-theftfake-websitesfileless-malwareinfostealermalicious-npmopenai-token-theftphishingpretalxprocess-hollowingrar-attachmentssupply-chainxsszero-click
What happened
Multiple active security incidents reported: a zero‑click XSS in pretalx (patched in v2026.1.0) could let attackers hijack conference organizer accounts, auto‑accept talks and demote admins; a phishing campaign using fake purchase order emails and RAR attachments deploys fileless PureLogs malware (uses process hollowing) to steal browser, crypto wallet and Discord data; a malicious Codex UI npm package (≈27k weekly downloads) was exfiltrating OpenAI refresh tokens enabling developer account takeover; and fake Anthropic websites are delivering a fileless infostealer targeting Claude Code users'
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- d864def91e696d412ec6f7634390143260924843bf40d78c67fdb18ca4064960
- Enrichment time
- 2026-06-02T08:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.