Hackers Exploit Magento Bug to Steal Payment Data from E-commerce Websites

Threat actors have been found exploiting a critical flaw in Magento to inject a persistent backdoor into e-commerce websites. The attack leverages CVE-2024-20720 (CVSS score: 9.1), which has been described by Adobe as a case of “improper neutralization of special elements” that could pave the way for arbitrary code execution. It was addressed by the company as part of…

Read More

Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating remote code execution, a new analysis has revealed. The audacious supply chain compromise, tracked as CVE-2024-3094 (CVSS score: 10.0), came to light last week when Microsoft engineer and PostgreSQL developer Andres Freund alerted…

Read More

umpServer Critical Flaws Let Attackers Execute Arbitrary Remote Code

The critical vulnerabilities in JumpServer’s Ansible that allowed attackers to execute arbitrary remote code have been patched. With a CVSS base score of 10, the critical vulnerabilities identified as CVE-2024-29201 and CVE-2024-29202 impact versions v3.0.0-v3.10.6. A jump server is an intermediary device that uses a supervised secure channel to route traffic across firewalls. It is often most advantageous…

Read More

Phishing-as-a-Service Platform Launched 20,000 Phishing Domains To Attack 100+ Countries

The cybersecurity landscape faces a new threat with the emergence of ‘darcula,’ a Phishing-as-a-Service (PhaaS) platform. This sophisticated service enables cybercriminals to launch phishing campaigns across over 20,000 domains, using advanced techniques to target over 100 countries. Unlike traditional phishing kits, ‘darcula’ utilizes modern technology such as JavaScript, React, Docker, and Harbor, akin to the tools used…

Read More