pwshub.com

Cisco merch shoppers stung in Magecart attack

Bad news for anyone who purchased a Cisco hoodie earlier this month: Suspected Russia-based attackers injected data-stealing JavaScript into the networking giant's online store selling Cisco-branded merch.

Cisco has since fixed the issue caused by a flaw in Adobe's Magento platform, which could have allowed crooks to steal shoppers' credit card details and other sensitive information at checkout.

"A Cisco-branded merchandise website that's hosted and administered by a third-party supplier was temporarily taken offline while a security issue was addressed," a Cisco spokesperson told The Register

"Based on our investigation, the issue impacted only a limited number of site users, and those users have been notified," the spokesperson said. "No credentials were compromised."

In this particular case, the unknown attacker(s) reportedly exploited CVE-2024-34102, a critical, 9.8-rated vulnerability in Adobe Magento software, widely used by eCommerce websites and a favorite target for thieves looking to intercept and steal transaction data from unsuspecting consumers. These types of Magento-targeting exploits are collectively called Magecart attacks.

CVE-2024-34102, which puts unpatched systems at risk of XML external entity injection (XXE) and remote code execution (RCE), was spotted by researcher Sergey Temnikov, who claims he reported the issue to Adobe and received a $9,000 bug bounty for this find.

Adobe patched the flaw on June 11, but a week later, eCommerce monitoring firm Sansec reported that only 25 percent of stores had upgraded their software. Meanwhile, criminals automated the attack to scale to thousands of sites, and multiple proof-of-concept exploits popped up on GitHub and elsewhere.

  • Magento shopping cart attack targets critical vulnerability revealed in early 2022
  • Cisco's Smart Licensing Utility flaws suggest it's pretty dumb on security
  • Let's kick off our summer with a pwn-me-by-Wi-Fi bug in Microsoft Windows
  • To patch this server, we need to get someone drunk

It appears Cisco's merchandise store was one of these unpatched sites, and at the time of the attack was running Magento 2.4 (Enterprise).

According to c/side researchers who analyzed the malicious JS code, it was hosted on a domain with a Russia-based IP address. The domain, rextension[.]net/za/, was registered on August 30.

"The domain's recent registration raises red flags as it could indicate a fly-by-night operation designed for quick exploitation before being abandoned," c/side's Himanshu Anand noted

"Obfuscated scripts like these are difficult to detect without specialized monitoring, making them especially dangerous for both website owners and their customers," he added. ®

Source: theregister.com

Related stories
1 month ago - It was only in February when Cisco laid off 4,000 people, or 5% of its workforce, as it struggled with a challenging economy and weak demand.Read Entire Article
1 month ago - An unprecedented period for an unparalleled force in cybercrime Feature For roughly two years, LockBit's ransomware operation was by far the most prolific of its kind, until the fateful events of February. After claiming thousands of...
1 week ago - CISA wants you to leap on Citrix and Ivanti issues. Adobe, Intel, SAP also bid for patching priorities Patch Tuesday Another Patch Tuesday has dawned, as usual with the unpleasant news that there are pressing security weaknesses and...
1 day ago - 'Lives will be lost' as Moscow ramps up offensive cyber military units Feature As Russian special forces push more overtly into online operations, network defenders should be on the hunt for digital intruders looking to carry out...
1 month ago - US workers who work remotely are 27 percent more likely to look forward to doing their job, according to a survey of over 4,400 employees aged 18...
Other stories
24 minutes ago - After California passed laws cracking down on AI-generated deepfakes of election-related content, a popular conservative influencer promptly sued,...
48 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
48 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
48 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
48 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.