Researchers uncover WebRTC skimmer bypassing traditional defenses
ID: 7315c60d-d28e-5902-a7f6-51fbe0e76412
STIX ID: report--7315c60d-d28e-5902-a7f6-51fbe0e76412
Feed Name: Security Affairs
Threat Score
Researchers uncovered a new payment-card skimmer that uses WebRTC DataChannels (DTLS-encrypted UDP) to fetch and exfiltrate malicious JavaScript, bypassing Content Security Policy and HTTP-based network detection; the skimmer exploits the PolyShell vulnerability in Magento/Adobe Commerce, has been actively scanned and used in the wild since March 19, 2026, and the report includes IoCs such as a hardcoded attacker IP and port.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
