pwshub.com

Thousands of online shops infected via CosmicSting flaw

Ray-Ban, National Geographic, Whirlpool, and Segway are among thousands of brands whose web stores were reportedly compromised by criminals exploiting the CosmicSting flaw in hope of stealing shoppers' payment card info as they order stuff online.

CosmicSting is the name for a critical vulnerability, CVE-2024-34102, in Adobe's Commerce and Magento software, and can be used to tamper with the pages of sites so that user data can quietly siphoned.

At least seven cybercrime gangs are said to be behind the ongoing cyber-heists exploiting CosmicSting. Over the summer here in the northern hemisphere, the crooks managed to hit 4,275 merchants that use Commerce and Magento to run their online shops, eCommerce monitoring firm Sansec reported this week. That's apparently five percent of all Adobe Commerce and Magento stores.

We've asked Sansec and the above-named victims for more details, and to determine whether they've been able to patch their websites yet. 

The Register spoke with Cisco last month, shortly after miscreants exploited CosmicSting to attack Switchzilla's Magento-based merch site, and a spokesperson assured us the security weakness had been addressed. "Based on our investigation, the issue impacted only a limited number of site users, and those users have been notified," the Cisco spokesperson said. "No credentials were compromised."

For what it's worth, CosmicSting can be exploited to not just steal card info, if available, but any information from a compromised site's page, such as customer login credentials and data.

Adobe's Commerce and Magento is widely used by online shopping sites, and thus attract crooks wanting to intercept and steal data from shoppers so that it can be used for fraud. Because of this, Magento-targeting exploits are collectively labeled Magecart attacks. Adobe Commerce is essentially powered by Magento, which the Photoshop giant bought in 2018 for $1.68 billion.

Getting down to details: CVE-2024-34102 is a 9.8-out-of-10 CVSS-rated unauthenticated XXE (XML External Entity) vulnerability that can be exploited to ultimately alter webpages served by vulnerable Adobe Commerce and Magento deployments.

In the case of these aforementioned attacks, the crooks use CosmicSting to add malicious JavaScript to checkout pages to steal customers' payment information as they type it in, or alter other pages to take other data. It was discovered and reported by Sergey Temnikov.

CVE-2024-34102 can be optionally combined with the high-severity CVE-2024-2961 – a glibc buffer overflow that's accessible on Linux from PHP – to achieve remote code execution on a vulnerable Commerce or Magento server host. That latter flaw can be used to install a backdoor on the machine for persistent access.

Adobe patched CVE-2024-34102 on June 11, but by then "automated attacks had already begun," according to Sansec.

At least seven distinct groups are running "large scale" CosmicSting campaigns, in which they use the flaw to obtain secret Magento keys from installations to generate tokens that grant unrestricted access to the Magento API, allowing sites to be edited.

With Magecart attacks, the first criminals to compromise a site will usually block others from moving in on their turf. "However, the CosmicSting vulnerability prevents this, leading to multiple groups fighting for control over the same store and evicting each other again and again," the Sansec forensics team noted.

In some cases, three different gangs were spotted squabbling over the same store, we're told.

As part of its ongoing analysis, Sansec has collected different CosmicSting loaders, each associated with different infrastructure and data-stealing methods, and published a full list of attack indicators, which is worth checking out, especially if you operate an online Magento shop.

Despite the ongoing warnings, "Sansec projects that more stores will get hacked in the coming months," the researchers wrote. ®

Source: go.theregister.com

Related stories
1 week ago - From allegations of lying about capabilities to fake reviews. Plus: Biden AI robocaller finally fined $6M The FTC has made good on its promise to crack down on suspected deceptive AI claims, announcing legal action against five outfits...
1 month ago - Enlarge / No, you haven't been "AI'd." That's a real crowd. Donald Trump may have coined a new term in his latest false attack on Kamala Harris'...
1 month ago - For competitive online gamers, your internet connection can make all the difference between winning and losing.
1 week ago - Want to enjoy a glass of great wine with dinner? You can find a red, white, pink or sparkling wine at every price point. You don't need to overspend...
3 weeks ago - As new options begin to emerge, it's an exciting time for satellite internet -- especially if you live in a rural area. Here's everything you need to know.
Other stories
5 minutes ago - 'You can build this in a few days – even as a very naïve developer' A pair of inventive Harvard undergraduates have created what they believe could be one of the most intrusive devices ever built – a wake-up call, they tell The Register,...
35 minutes ago - Bundles free government apps to help digital diplomacy – and maybe find some new customers Google Cloud will help India to spread its Digital Public Infrastructure – the suite of government apps it offers to help other nations – through...
2 hours ago - Here's today's NYT Mini Crossword answer. These answers will help you solve New York Times' popular crossword game, Mini Crossword, every day!
3 hours ago - Here's today's Wordle answer, plus a look at spoiler-free hints and past solutions. These clues will help you solve New York Times' popular puzzle game, Wordle, every day!
3 hours ago - Here's today's Strands answers and hints. These clues will help you solve The New York Times' popular puzzle game, Strands, every day.