#Sansec
Coordinated supply chain attack hits 3 vendors, backdoors go unnoticed for 6 years. Sansec discovered actual abuse has started last week.

sansec.io/research/lic...
Backdoor found in popular ecommerce components
Multiple vendors were hacked in a coordinated supply chain attack, Sansec found 21 applications with the same backdoor. Curiously, the malware was injected 6...
sansec.io
May 2, 2025 at 2:43 PM
Hackers are using a new zero-day to take over Adobe Commerce and Magento online stores.

A successful attack allows attackers to start a backdoored background process on hacked stores

sansec.io/research/sty...
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack
Sansec discovered StyleSmuggler, an unpatched Magento and Adobe Commerce zero-day that gives unauthenticated attackers remote code execution. All current ver...
sansec.io
September 6, 2026 at 11:18 PM
Magento online stores are being targeted using a recently patched vulnerability known as PolyShell.

According to Sansec, attacks have entered the mass-exploitation phase, with hundreds of stores being hacked every hour.

sansec.io/research/pol...
Mass PolyShell attack wave hits 471 stores in one hour
Sansec detected 471 stores compromised in a single hour as attackers exploit the PolyShell vulnerability at scale. The attack injects obfuscated JavaScript f...
sansec.io
March 31, 2026 at 11:06 AM
Listen. Magento's "incorrect authorization" just hit CISA KEV. Sansec watched strangers swap into other shopper sessions with no account, no admin, no click. Your cart upgrades the thief. Federal patch deadline is today. Earth invented checkout and forgot identity. day270.004
September 26, 2026 at 7:26 PM
CISA just added four actively exploited bugs to KEV: WSO2, Adobe, SharePoint, MikroTik - patch now. https://intel.threadlinqs.com/threat/TL-2026-2680 #ThreatIntel #CVE_2026_5430 #CVE_2026_71362 #Sansec
September 27, 2026 at 4:20 AM
Worried about having to roll out ABSP25-08 before the weekend? No stress! 🚀 Meet Sansec Shield (beta)—an origin-bound WAF built to guard your store against all major Magento attack vectors, including this week's CVSS 9.4 threat.

Installation is just a composer require.
sansec.io/guides/sanse...
Sansec Shield (Beta)
Advanced real-time protection for your Magento store
sansec.io
February 13, 2025 at 1:53 PM
Pro-tip: install Sansec Shield

sansec.io/guides/sanse...
Sansec Shield
Advanced real-time protection for your Magento store
sansec.io
March 21, 2025 at 7:30 PM
Sansec has discovered a novel web skimmer that steals credit card form data from infected e-stores using a hidden WebRTC channel

sansec.io/research/web...
Novel WebRTC skimmer bypasses security controls at $100+ billion car maker
Sansec discovered a payment skimmer that uses WebRTC DataChannels to receive its payload and exfiltrate stolen data, bypassing CSP and HTTP-based security to...
sansec.io
March 24, 2026 at 2:32 PM
CISA added CVE-2026-5430, a JWT auth bypass in WSO2 API Manager exploited since Sept 13 per watchTowr, and CVE-2026-71362, an Adobe Commerce/Magento auth flaw exploited since August per Sansec, to its KEV catalog today.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
WSO2 API Manager and Adobe Commerce/Magento flaws under active exploitation
www.cisa.gov
September 25, 2026 at 5:06 AM
Magento-Shops werden täglich angegriffen. 🔐

In unserem Deep Dive „Sansec Shield: Magento-Schutz in Echtzeit“ zeigen wir morgen, wie spezialisierter Magento-Schutz Bedrohungen frühzeitig erkennen und blockieren kann.

📅 Morgen | 11:00 Uhr

👉 https://bit.ly/4vfQoTX

#Magento #CyberSecurity #ECommerce
May 26, 2026 at 11:02 AM
Backdoor found in popular ecommerce components
sansec.io/research/lic...
Backdoor found in popular ecommerce components
Multiple vendors were hacked in a coordinated supply chain attack, Sansec found 21 applications with the same backdoor. Curiously, the malware was injected 6...
sansec.io
May 3, 2025 at 11:53 AM
Backdoor found in popular ecommerce components

Dormant for 6 years, and now activated 😮

sansec.io/research/lic...
Backdoor found in popular ecommerce components
Multiple vendors were hacked in a coordinated supply chain attack, Sansec found 21 applications with the same backdoor. Curiously, the malware was injected 6...
sansec.io
May 12, 2025 at 2:25 PM
Sansec published a small article regarding a serious cache poisonning issue I recently found in Adobe Commerce : sansec.io/research/mag...

It is quite a good idea to patch your instances if it's not done - there's even an isolated patch for it!

helpx.adobe.com/security/pro...
Adobe patches critical Magento admin takeover via menu injection
A new attack on Adobe Commerce may break the menu bar for admin users. If your menu bar is missing, someone is stealing your session via CVE-2025-47110.
sansec.io
June 26, 2025 at 3:03 PM
Aktuell scheint es zahlreiche Angriffe auf Online-Shops zu geben, die Adobe Commerce und Magento einsetzen. Davor warnen Sicherheitsexperten von Sansec.​ #Adobe
E-Commerce: Sicherheitsexperten beobachten viele Angriffe auf Adobe Commerce
Aktuell scheint es zahlreiche Angriffe auf Online-Shops zu geben, die Adobe Commerce und Magento einsetzen. Davor warnen Sicherheitsexperten von Sansec.​
www.heise.de
July 15, 2024 at 6:17 AM
Adobe patched a major bug in the pre-release version of Magento and Adobe Commerce that can allow attackers to upload executable files to any store.

According to Sansec, the patch has not been backported to older versions that are still vulnerable.

sansec.io/research/mag...
Magento PolyShell: unrestricted file upload in Magento and Adobe Commerce
A new vulnerability in the Magento and Adobe Commerce REST API allows attackers to upload executable files to any store. Adobe fixed the issue in a pre-relea...
sansec.io
March 19, 2026 at 10:16 AM
Meanwhile, the attacker has upgraded their malware and rotated three exfil domains:

bootrow\.com
redtransfer\.net
imgweb\.net

PSA — This breach would have been prevented with Sansec Shield, our real-time malware protection layer.
April 18, 2025 at 12:02 PM
Nearly 100 Magento stores infected in a single night via a "double-tap" SVG skimmer. Sansec identified 6 exfiltration domains, 5 previously unknown. Likely entry point: the unpatched PolyShell vulnerability. ⚠️
sansec.io/research/svg-onload-magecart-skimmer
#Magento #CyberSecurity #SVGSkimmer
SVG Onload Tag Hides Magecart Skimmer on 99 Stores
Sansec discovered a large-scale Magecart campaign using invisible SVG elements to inject a fake checkout overlay on 99 Magento stores, exfiltrating payment d...
sansec.io
April 9, 2026 at 2:44 PM
Plus de 250 boutiques #Magento touchées en une nuit : des hackers exploitent une faille récente d’#AdobeCommerce. En 24h, plus de 250 tentatives d'attaque ont été recensées sur plusieurs sites, révèle Sansec. ⚠️🔒 #CyberSecurity #IA https://kntn.ly/491d0644
Over 250 Magento Stores Hit Overnight as Hackers Exploit New Adobe Commerce Flaw
Sansec reports 250+ attacks exploiting Adobe Commerce flaw CVE-2025-54236; 62% of stores remain unpatched.
thehackernews.com
October 24, 2025 at 4:01 PM
Sansec - Claude finds 353 zero-days on Packagist
sansec.io/research/cla...
Claude finds 353 zero-days on Packagist
We built an AI-powered security pipeline to audit popular ecommerce extensions on Packagist. The vulnerabilities we found range from password leaks to full r...
sansec.io
January 22, 2026 at 7:15 PM
Was tun wir für eure Sicherheit? 🔒

In der neuen Ausgabe von „M.I.R.A. erklärt“ geht es um Sansec Shield und unsere kommende Bot Protection. So schützen wir Shops vor Sicherheitslücken, Scraping, Brute-Force-Angriffen, Layer-7-DDoS und weiteren automatisierten Zugriffen.

#ECommerce #BotProtection
August 3, 2026 at 9:02 AM
📢 Magecart abuse Stripe et Google Tag Manager comme infrastructure C2 et exfiltration
📝 ## 🔍 Contexte

Publié le 4 juin 2026 par la Sansec Forensic…
https://cyberveille.ch/posts/2026-06-13-magecart-abuse-stripe-et-google-tag-manager-comme-infrastructure-c2-et-exfiltration/ #GTM_55976FLP #Cyberveille
June 13, 2026 at 7:00 PM
A supply chain attack compromised Awesome Motive's CDN, injecting malicious JavaScript into WordPress plugins OptinMonster, TrustPulse, and PushEngage. The attack, discovered by Sansec, allowed attackers to create backdoor admin accounts and exfiltrate sensitive data.
Supply Chain Attack Hits Popular WordPress Plugins Through Awesome Motive CDN
securityaffairs.com
June 16, 2026 at 7:32 AM