Navigation
Search
|
Hundreds of E-Commerce Sites Hacked In Supply-Chain Attack
Monday May 5, 2025. 10:50 PM , from Slashdot
![]() 'Since the backdoor allows uploading and executing arbitrary PHP code, the attackers have full remote code execution (RCE) and can do essentially anything they want,' the representative wrote. 'In nearly all Adobe Commerce/Magento breaches we observe, the backdoor is then used to inject skimming software that runs in the user's browser and steals payment information (Magecart).' The three software suppliers identified by Sansec were Tigren, Magesolution (MGS), and Meetanshi. All three supply software that's based on Magento, an open source e-commerce platform used by thousands of online stores. A software version sold by a fourth provider named Weltpixel has been infected with similar code on some of its customers' stores, but Sansec so far has been unable to confirm whether it was the stores or Weltpixel that were hacked. Adobe has owned Megento since 2018. Read more of this story at Slashdot.
https://it.slashdot.org/story/25/05/05/2034207/hundreds-of-e-commerce-sites-hacked-in-supply-chain-a...
Related News |
25 sources
Current Date
May, Tue 6 - 14:42 CEST
|