ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardBriefings › Sansec reports an unpatched, actively exploited zero-day backdooring Magento and Adobe Commerce stores
IT SECURITY DESK

Sansec reports an unpatched, actively exploited zero-day backdooring Magento and Adobe Commerce stores

A no-login remote code execution flaw in Magento Open Source and Adobe Commerce is under active exploitation with no fix available, the day's most urgent item among a run of exploited flaws and breaches.

The Hacker News reports that attackers are exploiting a new, unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on a store's server without logging in. The report attributes the discovery to Dutch e-commerce security firm Sansec, which published its advisory on September 5 and said the flaw is being used to backdoor online stores. There is no patch. If you run Magento Open Source or Adobe Commerce, follow Sansec's advisory, watch server-side file writes and unexpected admin or process activity, and treat any exposed storefront as a live target until a vendor fix ships.

Several other products are named as under attack. SecurityWeek reports that a vulnerability in the Elementor Pro WordPress plugin, described as an arbitrary file upload issue in the function that handles form submissions, is being exploited to hack sites. The Hacker News reports, citing the Arctic Wolf Adversary Research Team, that attackers are exploiting newly disclosed PaperCut flaws — an authentication bypass and a remote code execution bug — to steal credentials in attacks on the education sector in the U.S. and Europe. BleepingComputer reports that a cybercriminal operation is using thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain.

On patched flaws: The Hacker News reports that Broadcom released security updates for VMware Workstation and Fusion, including a critical integer-overflow bug that a local attacker could use to execute code on the host; apply Broadcom's updates. SecurityWeek reports that HPE patched critical remote code execution flaws in AOS-CX that an unauthenticated attacker could exploit by sending crafted packets to achieve RCE with elevated privileges; apply HPE's updates.

Two disclosures round out the day. The Hacker News reports that JetBrains is urging Cadence users to immediately revoke or rotate all credentials after threat actors exploited a recently disclosed critical TeamCity vulnerability to breach its environment and extract AWS credentials. The Hacker News also reports that Trezor disclosed that a breach at its shipping provider ShipMonk exposed 67,000 U.S. customers' names, email addresses, phone numbers, shipping addresses, and order numbers.

Related