Big names among thousands infected by payment-card-stealing CosmicSting crooks
ID: 4a2b3611-f943-58b5-9785-44513821c8da
STIX ID: report--4a2b3611-f943-58b5-9785-44513821c8da
Feed Name: The Register (Security)
A critical unauthenticated XXE vulnerability (CVE-2024-34102, 'CosmicSting') in Adobe Commerce/Magento has been actively exploited since before an official patch, allowing attackers to inject malicious JavaScript into e‑commerce pages to steal payment cards, credentials, and other customer data; Sansec reports roughly 4,275 compromised stores (about 5% of installations), multiple criminal groups running automated campaigns and published IoCs, and risk of persistent backdoors if combined with a separate glibc/PHP flaw (CVE-2024-2961).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
