Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Hackers exploit Magento vulnerability to steal e-commerce website payment data
    Cyber Security

    Hackers exploit Magento vulnerability to steal e-commerce website payment data

    techempireBy techempire3 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportApril 6, 2024Editorial DepartmentSkimmers/Threat Intelligence

    Magento error

    We discovered that threat actors exploited a critical flaw in Magento to inject persistent backdoors into e-commerce websites.

    The attack exploited CVE-2024-20720 (CVSS score: 9.1), which Adobe describes as a case of “improper neutralization of a special element” that could pave the way for arbitrary code execution.

    The company addressed this issue in a security update released on February 13, 2024.

    Sansec said it discovered a “crafted layout template” in the database that was used to automatically inject malicious code to execute arbitrary commands.

    “The attacker combined the Magento layout parser with the beberlei/assert suite (preset installation) to execute system commands,” the company said.

    Internet security

    “Since the layout block is associated with the checkout cart, whenever the This command will be executed when /checkout/cart. “

    The command in question is sed, which is used to insert a code execution backdoor, which is then responsible for serving up the Stripe payment browser to capture financial information and exfiltrate it to another compromised Magento store.

    The development comes as the Russian government has charged six people with using skimmer malware to steal credit card and payment information from foreign e-commerce stores since at least late 2017.

    The suspects are Denis Primachenko, Alexander Asayev, Alexander Basov, Dmitry Kolpakov, Vladislav Patuk and Anton Tolmachev. The Future News-Record reported, citing court documents, that the arrests were made a year ago.

    “As a result, members of the hacker group illegally obtained information on nearly 160,000 payment cards of foreign citizens and then sold this information through shadow Internet sites,” the Prosecutor General’s Office of the Russian Federation said.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Pokémon Trading Card Website Making 100k!

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    GTA 6 Release Date

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.