logo

Hackers inject malicious JS in Cisco store to steal credit cards, credentials

ID: 8a5d1610-232c-53a8-b94a-901d613f526e

STIX ID: report--8a5d1610-232c-53a8-b94a-901d613f526e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-04

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Cisco's branded merchandise website was compromised with obfuscated JavaScript that exfiltrates checkout information (credit card details, postal address, phone, email, and login credentials). Researchers link the compromise to the CosmicSting XXE vulnerability (CVE-2024-34102) in Adobe Commerce/Magento; the malicious script was delivered from a newly registered domain and the site has been taken offline while impacted users are being notified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.