PolyShell attacks target 56% of all vulnerable Magento stores
ID: aea55f1f-c1c7-54cd-abd4-cddab867bf82
STIX ID: report--aea55f1f-c1c7-54cd-abd4-cddab867bf82
Feed Name: Bleeping Computer
Sansec reports widespread active exploitation of the 'PolyShell' vulnerability in Magento 2's REST API—mass scanning and attacks began March 19, impacting 56.7% of vulnerable stores—and notes that Adobe's fix is only available in a beta release. In some of these incidents attackers deliver a novel WebRTC-based payment-card skimmer that exfiltrates data over DTLS/UDP (bypassing CSP and using forged SDP and script-nonce reuse), and Sansec has published IOCs and scanning IP addresses to help defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
