#ecommercesecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ecommercesecurity, aggregated by home.social.
-
Magento Zero-Day Exploited to Install Persistent Backdoors
A critical Magento zero-day vulnerability, dubbed StyleSmuggler, is being actively exploited to install persistent backdoors on e-commerce stores, with attacks detected as early as September 4. All current versions of Magento Open Source and Adobe Commerce are affected, leaving stores vulnerable until a patch is released.
#MagentoZeroday #AdobeCommerce #SupplyChain #EcommerceSecurity #EmergingThreats
-
StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now.
#StyleSmuggler #Magento #AdobeCommerce #ZeroDay #RCE #eCommerceSecurity #Sansec #Infosec
-
Third-party breach, 38M impacted, European e-commerce sector.
ManoMano disclosed unauthorized access linked to a subcontracted customer support provider. Exposed data reportedly includes PII and support communications.
Authorities notified: CNIL, ANSSI.
Passwords not reportedly accessed.
Subcontractor access revoked.Key risk vectors:
– SaaS support platforms
– Vendor access governance
– Over-retention of ticketing data
– Centralized customer communication logs
– Supply chain attack surface expansionThis case reinforces that vendor monitoring must go beyond contractual clauses — continuous assessment, least privilege enforcement, data minimization strategies.
How mature is your third-party risk telemetry?
Engage below.Follow @technadu for high-signal infosec reporting.
Repost to amplify awareness across the security community.
#Infosec #ThirdPartyRisk #VendorSecurity #SupplyChainSecurity #DataBreach #GDPRCompliance #EcommerceSecurity #CyberRiskManagement #SecurityOperations #GRC
-
A dangerous flaw in Adobe Commerce lets hackers hijack customer sessions with zero effort—and 60% of Magento stores are still unpatched. Is your business vulnerable?
#sessionreaper
#adobecommerce
#magento
#cve202554236
#ecommercesecurity -
🚨 Critical Magento & Adobe Commerce Flaw (CVE-2025-54236 – SessionReaper) 🚨
Impact: Customer account takeover + unauthenticated remote code execution (CVSS 9.1 Critical).
👉 Full details and action steps: https://hostvix.com/sessionreaper-critical-magento-adobe-commerce-vulnerability-cve-2025-54236/
#Magento #AdobeCommerce #SessionReaper #CVE202554236 #CVE #Infosec #CyberSecurity #AppSec #WebSecurity #SecOps #BlueTeam #RedTeam #ThreatIntel #Vulnerability #PatchNow #ZeroDay #Exploit #EcommerceSecurity #DataSecurity #SecurityUpdate