Hackers Exploit Magento Bug to Steal Payment Data from E-commerce Websites
ID: 5f8b33e3-3eb4-5ce9-b19c-d89b1dc0ef5a
STIX ID: report--5f8b33e3-3eb4-5ce9-b19c-d89b1dc0ef5a
Feed Name: The Hacker News
Attackers are actively exploiting CVE-2024-20720 (CVSS 9.1) in Magento to inject a persistent layout-template backdoor that executes system commands via the Magento layout parser and the beberlei/assert package; the injected code uses sed to install a Stripe payment skimmer that captures and exfiltrates payment card data, executing on requests to the checkout cart. Adobe released fixes on Feb 13, 2024, and security vendor Sansec reported the technique and observed skimmer delivery; the report also references prior criminal activity and arrests tied to payment-card skimming operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
