Skip to main content

Hundreds of E-Commerce Sites Hacked In Supply-Chain Attack

5 days 3 hours ago
An anonymous reader quotes a report from Ars Technica: Hundreds of e-commerce sites, at least one owned by a large multinational company, were backdoored by malware that executes malicious code inside the browsers of visitors, where it can steal payment card information and other sensitive data, security researchers said Monday. The infections are the result of a supply-chain attack that compromised at least three software providers with malware that remained dormant for six years and became active only in the last few weeks. At least 500 e-commerce sites that rely on the backdoored software were infected, and it's possible that the true number is double that, researchers from security firm Sansec said. Among the compromised customers was a $40 billion multinational company, which Sansec didn't name. In an email Monday, a Sansec representative said that "global remediation [on the infected customers] remains limited." "Since the backdoor allows uploading and executing arbitrary PHP code, the attackers have full remote code execution (RCE) and can do essentially anything they want," the representative wrote. "In nearly all Adobe Commerce/Magento breaches we observe, the backdoor is then used to inject skimming software that runs in the user's browser and steals payment information (Magecart)." The three software suppliers identified by Sansec were Tigren, Magesolution (MGS), and Meetanshi. All three supply software that's based on Magento, an open source e-commerce platform used by thousands of online stores. A software version sold by a fourth provider named Weltpixel has been infected with similar code on some of its customers' stores, but Sansec so far has been unable to confirm whether it was the stores or Weltpixel that were hacked. Adobe has owned Megento since 2018.

Read more of this story at Slashdot.

BeauHD

Microsoft Shuts Down Skype

5 days 4 hours ago
Microsoft officially shuttered Skype on May 5, ending the pioneering video chat service's 22-year run. The closure, announced in February, completes Skype's absorption into Microsoft Teams, the company's Slack competitor. Users opening Skype apps will now be redirected to Teams. The only surviving component is the Skype Dial Pad, which remains available within Microsoft Teams Free for subscribers to make calls to traditional phone numbers. The once-dominant video calling platform was purchased by Microsoft for $8.5 billion in 2011, replacing the company's Windows Live Messenger. Created in 2003 by developers behind Kazaa file-sharing software, Skype became synonymous with video calling during broadband internet's expansion. Skype's decline accelerated after Microsoft's acquisition, with unpopular redesigns and competition from Zoom, which captured market share during the COVID-19 pandemic. Microsoft began phasing out Skype in 2017, starting with Skype for Business, while bundling Teams with Office applications until regulatory intervention forced their separation.

Read more of this story at Slashdot.

msmash