Skip to main content
Security Products

Unpatched Magento flaw is being exploited to backdoor online stores

Unpatched Magento flaw is being exploited to backdoor online stores Image: Primary
Attackers began exploiting an unpatched vulnerability in Magento Open Source and Adobe Commerce on September 4, according to Sansec. The company said the flaw, which it calls StyleSmuggler, allows unauthenticated code execution on a store server and can install a persistent backdoor. Sansec said current Magento versions are affected and that it reproduced the chain on clean 2.4.7, 2.4.8 and 2.4.9 installations. Disrex separately reported responding to two compromised stores, but Adobe had not issued an advisory, CVE, patch or workaround.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure AI
Infrastructure AI

TCS-backed HyperVault commits $7.4 billion to southern India AI campus

Tata Consultancy Services said its HyperVault unit and partners have committed 700 billion rupees ($7.4 billion) to establish a large-scale artificial-intelligence data-center campus in southern India. The commitment expands TCS's...

Capital AI
Capital AI

Report says Anthropic IPO timetable shifts into October

Anthropic is now expected to make its IPO prospectus public in late September and begin marketing no earlier than mid-October, according to people familiar with the matter cited by Reuters. The company had been expected to publis...

Infrastructure AI
Infrastructure AI

TCS unit commits $7.4 billion for Hyderabad AI data-center campus

Tata Consultancy Services said its HyperVault unit and partners have committed 700 billion rupees, about $7.4 billion, to an AI data-center campus in Hyderabad. The company said the 264-acre site, for which land has been secured, ...

Security Policy
Security Policy

Berlin reviews ransomware data release after rejecting ransom

Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...

Security Infrastructure
Security Infrastructure

JetBrains tells Cadence users to rotate credentials after TeamCity breach

JetBrains is telling Cadence users to revoke or rotate credentials and secrets after attackers exploited a critical TeamCity vulnerability to breach a Cadence environment. The company said the attackers accessed a 2024 server back...