Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ Breach of Software Maker Used To Backdoor Ecommerce Servers

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Breach of Software Maker Used To Backdoor Ecommerce Servers


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: yro.slashdot.org

An anonymous reader quotes a report from Ars Technica: FishPig, a UK-based maker of e-commerce software used by as many as 200,000 websites, is urging customers to reinstall or update all existing program extensions after discovering a security breach of its distribution server that allowed criminals to surreptitiously backdoor customer systems. The unknown threat actors used their control of FishPig's systems to carry out a supply chain attack that infected customer systems using FishPig's fee-based Magento 2 modules with Rekoobe, a sophisticated backdoor discovered in June. Rekoobe masquerades as a benign SMTP server and can be activated by covert commands related to handling the startTLS command from an attacker over the Internet. Once activated, Rekoobe provides a reverse shell that allows the threat actor to remotely issue commands to the infected server. "We are still investigating how the attacker accessed our systems and are not currently sure whether it was via a server exploit or an application exploit," Ben Tideswell, the lead developer at FishPig, wrote in an email. "As for the attack itself, we are quite used to seeing automated exploits of applications and perhaps that is how the attackers initially gained access to our system. Once inside though, they must have taken a manual approach to select where and how to place their exploit." FishPig is a seller of Magento-WordPress integrations. Magento is an open source e-commerce platform used for developing online marketplaces. The supply-chain attack only affects paid Magento 2 modules. Tideswell said the last software commit made to its servers that didn't include the malicious code was made on August 6, making that the earliest possible date the breach likely occurred. Sansec, the security firm that discovered the breach and first reported it, said the intrusion began on or before August 19. Tideswell said FishPig has already "sent emails to everyone who has downloaded anything from FishPig.co.uk in the last 12 weeks alerting them to what's happened." Tideswell declined to say how many active installations of its paid software there are. This post indicates that the software has received more than 200,000 downloads, but the number of paid customers is smaller. In a disclosure published after the Sansec advisory, FishPig describes how the intruders pulled off the intrusion and remained hidden for so long.

Read more of this story at Slashdot.

...



๐Ÿ“Œ Breach of Software Maker Used To Backdoor Ecommerce Servers


๐Ÿ“ˆ 58.69 Punkte

๐Ÿ“Œ eCommerce Payment System โ€“ How to Choose the Best One for Your eCommerce Startup?


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25093: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25092: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25091: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25088: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25090: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25089: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25087: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ Low CVE-2020-25086: Ecommerce-codeigniter-bootstrap project Ecommerce-codeigniter-bootstrap


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ No backdoor, no backdoor... you're a backdoor! Huawei won't spy for China or anyone else, exec tells MPs


๐Ÿ“ˆ 25.06 Punkte

๐Ÿ“Œ LightNeuron, a Turlaโ€™s backdoor used to compromise exchange mail servers


๐Ÿ“ˆ 24.32 Punkte

๐Ÿ“Œ New Microsoft Exchange Exploit Used by Ransomware Gang to Breach Servers


๐Ÿ“ˆ 22.31 Punkte

๐Ÿ“Œ PrestaShop Confirms Zero Day Attacks Hitting eCommerce Servers


๐Ÿ“ˆ 21.86 Punkte

๐Ÿ“Œ Multecart eCommerce Digital Multivendor marketplace shopping Cart - CMS v3.0 backdoor account Vulnerability


๐Ÿ“ˆ 21.84 Punkte

๐Ÿ“Œ Active Ecommerce CMS 6.4.0 Backdoor Account


๐Ÿ“ˆ 21.84 Punkte

๐Ÿ“Œ How data poisoning is used to trick fraud detection algorithms on ecommerce sites


๐Ÿ“ˆ 21.07 Punkte

๐Ÿ“Œ CVE-2022-25813 | Apache OFBiz up to 18.12.05 Ecommerce Plugin Subject special elements used in a template engine


๐Ÿ“ˆ 21.07 Punkte

๐Ÿ“Œ Creative Software Maker Affinity Informs Customers of Forum Breach


๐Ÿ“ˆ 20.88 Punkte

๐Ÿ“Œ Faszinierenยญde Kreaturen, grandiose Soundยญmaschinen, verrรผckte Maker-Projekte: Maker Faire erneut in Berlin


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker: Pocket Maker, der Mini-3D-Drucker


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Faszinierenยญde Kreaturen, grandiose Soundยญmaschinen, verrรผckte Maker-Projekte: Maker Faire erneut in Berlin


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker: Pocket Maker, der Mini-3D-Drucker


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker Share: neue Plattform fรผr Maker


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker auf der ars electronica: Mini Maker Faire Linz


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Zwischen Hebocon und Maker Education: die Mini Maker Faire Zรผrich 2018


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker aus aller Welt โ€“ auf der Maker Faire Berlin


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker Faire: Maker Media stellt seine Arbeit ein


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Super Mario Maker-Fan wรผnscht sich einen 'Pokรฉmon Maker' & liefert Ideen


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Mini Maker Faire Aurich: Maker-Treffen im Nordwesten


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Das finale Super Mario Maker 2-Update fรผgt den โ€œWorld Makerโ€-Modus und mehr hinzu


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Nintendo Super Mario Maker 2: Neues Update mit World Maker kommt am 22. April


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Maker-Spiel "Mini Maker" ausprobiert: Kreatives Schrottbasteln


๐Ÿ“ˆ 20.41 Punkte

๐Ÿ“Œ Wochenendtipp: Maker Faire โ€“ Hannovers Ideen-Feuerwerk und Maker-Treff


๐Ÿ“ˆ 20.41 Punkte











matomo