logo

Big names among thousands infected by payment-card-stealing CosmicSting crooks

ID: 4a2b3611-f943-58b5-9785-44513821c8da

STIX ID: report--4a2b3611-f943-58b5-9785-44513821c8da

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-10-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical unauthenticated XXE vulnerability (CVE-2024-34102, 'CosmicSting') in Adobe Commerce/Magento has been actively exploited since before an official patch, allowing attackers to inject malicious JavaScript into e‑commerce pages to steal payment cards, credentials, and other customer data; Sansec reports roughly 4,275 compromised stores (about 5% of installations), multiple criminal groups running automated campaigns and published IoCs, and risk of persistent backdoors if combined with a separate glibc/PHP flaw (CVE-2024-2961).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.