PureLogs Variant Steals Data via Purchase Order Lures
2026-05-27T08:52:15Z•729fa1aecd0ef517f9fa9a98d7ad13e82ece09dadb72bc75a6f55c7e01549a20
Android-malwareCERT-InGitHub-breachGrafana-breachICOLinux-ptraceMicrosoft-ExchangeNCSCOAuth-token-hijackRATVSCode-extensionbackdoorcredential-theftinfostealerkernel-flawlaw-enforcement-takedown','europol','interpol','ransomware-enab1malwarenpmpatchingphishingphishing-kitprivilege-escalationsupply-chainvulnerabilityzero-day
What happened
Infosecurity Magazine roundup: multiple high-impact phishing and credential-theft campaigns (PureLogs purchase-order lures, Chinese live credential interception platforms, FBI-noted Kali365 OAuth token hijack), expanding malware-as-a-service and mobile threats (BTMOB Android RAT, Gremlin stealer, Iran-linked MiniFast backdoor), and large supply-chain/code-supply incidents (malicious Nx Console/VS Code extension, Grafana/TanStack breach, npm Mini Shai‑Hulud, Avada Builder flaws). Security landscape also features critical vulnerabilities and zero-days (Microsoft on‑prem Exchange zero-day, FrAgNe
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 729fa1aecd0ef517f9fa9a98d7ad13e82ece09dadb72bc75a6f55c7e01549a20
- Enrichment time
- 2026-05-27T08:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.