Get a Pentest and security assessment of your IT network.

News

Multiple 0days used by Magecart

Thieves are exploiting unpublished security flaws (aka 0days) in popular store extension software. The attack method is the same: PHP Object Injection (POI) This attack vector abuses PHPs unserialize() function to inject their own PHP code into the site. With that, they are able to modify the database or any Javascript files. Attackers are now probing Magento stores in the wild for these extensions. If you are running any of them, youd better disable them quickly.”]

Source: https://gwillem.gitlab.io/2018/10/23/magecart-extension-0days/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months