Investors Hangout Stock Message Boards Logo
  • Mailbox
  • Favorites
  • Boards
    • The Hangout
    • NASDAQ
    • NYSE
    • OTC Markets
    • All Boards
  • Whats Hot!
    • Recent Activity
    • Most Viewed Boards
    • Most Viewed Posts
    • Most Posted
    • Most Followed
    • Top Boards
    • Newest Boards
    • Newest Members
  • Blog
    • Recent Blog Posts
    • Recently Updated
    • News
    • Stocks
    • Crypto
    • Investing
    • Business
    • Markets
    • Economy
    • Real Estate
    • Personal Finance
  • Market Movers
  • Interactive Charts
  • Login - Join Now FREE!
  1. Home ›
  2. Stock Message Boards ›
  3. Stock Boards ›
  4. NextPlat Corp. (NXPL) Message Board

Hackers Exploit Bug in Magento to Access Payment D

Message Board Public Reply | Private Reply | Keep | Replies (0)                   Post New Msg
Edit Msg () | Previous | Next


Post# of 166
(Total Views: 138)
Posted On: 04/10/2024 5:36:04 PM
Avatar
Posted By: NetworkNewsWire
Hackers Exploit Bug in Magento to Access Payment Data on eCommerce Sites

A critical flaw in the open-source e-commerce platform Magento has allowed hackers to make backdoors into e-commerce websites and steal payment data. Computer software company Adobe Inc. describes the error, CVE-2024-2072, as the “improper neutralization of special elements” that could allow attackers to make arbitrary code executions without any user interaction.

Adobe addressed the vulnerability on Feb. 13, 2024, as part of a batch of security updates while e-commerce security company Sansec announced that it had found a database layout template that was used to “inject malicious code” automatically. Hackers could then use this code to execute commands arbitrarily by combining the “cleverly crafted layout” with the beberlei/assert package.

According to Sansec, this vulnerability could be exploited any time a user requested <store>/checkout/cart as checkout cart is tied to the layout block, allowing them to execute system commands. More specifically, hackers could execute the command “sed,” enabling them to insert a code execution backdoor that would then deliver a Stripe payment skimmer to capture and retrieve financial information to another infiltrated Magento store.

News of the Magento vulnerability comes after Moscow charged six individuals for using similar skimmer malware to steal payment and credit card information from foreign virtual stores for at least six years. Reports citing court documents show that Alexander Aseyev, Denis Priymachenko, Alexander Basov, Vladislav Patyuk, Anton Tolmachev and Dmitry Kolpakov were arrested as suspects last year.

In a rare move, the prosecutor general’s office of the Russian Federation publicly noted that the hacker group focused on foreign e-commerce platforms and stole the information of close to 160,000 payment cards before selling them via shadow internet sites. SANS Institute instructor Will Thomas said the hacker group used Magecart, a tactic for stealing information that was initially used by the group behind the initial Magento attacks.

This Magecart-like tactic saw the hackers inject malicious code into web pages where customers typically enter payment information, including checkout pages to capture CVV codes, credit card data and other sensitive private information. The hacker group would then store this data on its servers before using darknet forums to sell the information to operations that perpetuate credit card debt.

With dozens of groups carrying out similar hacking operations across the globe, Thomas noted that attributing fault to one group can be quite difficult. Recorded Future’s Insikt Group estimates that in 2022 alone, such groups gathered close to 60 million credit-card payment records and posted them on dark web forums.

Entities in sensitive segments of e-commerce such as healthcare e-commerce, including NextPlat Corp. (NASDAQ: NXPL) (NASDAQ: NXPLW), are probably concerned about how other hacks of this nature can be prevented in the future since it would be damaging if the sensitive personal information of patients buying their medications and supplies from online stores is compromised by hackers.

NOTE TO INVESTORS: The latest news and updates relating to NextPlat Corp. (NASDAQ: NXPL, NXPLW) are available in the company’s newsroom at https://ibn.fm/NXPL

Please see full terms of use and disclaimers on the BioMedWire website applicable to all content provided by BMW, wherever published or re-published: http://BMW.fm/Disclaimer




(0)
(0)




NextPlat Corp. (NXPL) Stock Research Links


  1.  
  2.  


  3.  
  4.  
  5.  






Investors Hangout

Home

Mailbox

Message Boards

Favorites

Whats Hot

Blog

Settings

Privacy Policy

Terms and Conditions

Disclaimer

Contact Us

Whats Hot

Recent Activity

Most Viewed Boards

Most Viewed Posts

Most Posted Boards

Most Followed

Top Boards

Newest Boards

Newest Members

Investors Hangout Message Boards

Welcome To Investors Hangout

Stock Message Boards

American Stock Exchange (AMEX)

NASDAQ Stock Exchange (NASDAQ)

New York Stock Exchange (NYSE)

Penny Stocks - (OTC)

User Boards

The Hangout

Private

Global Markets

Australian Securities Exchange (ASX)

Euronext Amsterdam (AMS)

Euronext Brussels (BRU)

Euronext Lisbon (LIS)

Euronext Paris (PAR)

Foreign Exchange (FOREX)

Hong Kong Stock Exchange (HKEX)

London Stock Exchange (LSE)

Milan Stock Exchange (MLSE)

New Zealand Exchange (NZX)

Singapore Stock Exchange (SGX)

Toronto Stock Exchange (TSX)

Contact Investors Hangout

Email Us

Follow Investors Hangout

Twitter

YouTube

Facebook

Market Data powered by QuoteMedia. Copyright © 2025. Data delayed 15 minutes unless otherwise indicated (view delay times for all exchanges).
Analyst Ratings & Earnings by Zacks. RT=Real-Time, EOD=End of Day, PD=Previous Day. Terms of Use.

© 2025 Copyright Investors Hangout, LLC All Rights Reserved.

Privacy Policy |Do Not Sell My Information | Terms & Conditions | Disclaimer | Help | Contact Us