logo

Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks

ID: e3934566-21a6-574d-8d6f-947430d9d9b3

STIX ID: report--e3934566-21a6-574d-8d6f-947430d9d9b3

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2024-10-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Adobe Commerce and Magento stores are being widely compromised by the 'CosmicSting' vulnerability (CVE-2024-34102), which when chained with CVE-2024-2961 can enable remote code execution; attackers have injected payment-skimming JavaScript to steal credit card and customer data from roughly 4,275 sites, multiple financially motivated groups are involved, and Adobe/Sansec have issued patches and emergency hotfixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.