Over 4,000 Adobe Commerce, Magento shops hacked in CosmicSting attacks
ID: e3934566-21a6-574d-8d6f-947430d9d9b3
STIX ID: report--e3934566-21a6-574d-8d6f-947430d9d9b3
Feed Name: Bleeping Computer
Threat Score
Adobe Commerce and Magento stores are being widely compromised by the 'CosmicSting' vulnerability (CVE-2024-34102), which when chained with CVE-2024-2961 can enable remote code execution; attackers have injected payment-skimming JavaScript to steal credit card and customer data from roughly 4,275 sites, multiple financially motivated groups are involved, and Adobe/Sansec have issued patches and emergency hotfixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
