惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
小众软件
小众软件
D
Docker
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
V2EX
博客园 - 叶小钗
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
IT之家
IT之家
博客园 - 司徒正美
M
MIT News - Artificial intelligence
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog

Sansec - experts in eCommerce security

GorgonAgora: 4,800+ fake storefronts skim cards across hundreds of impersonated brands Sansec adds support for Sylius 1 & 2 Critical vulnerability in Mirasvit Cache Warmer for Magento Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts Composer vulnerability leaks GitHub tokens, threatens PHP supply chain Over 200 PrestaShop stores expose installer, allowing full takeover ClickFix malware hits DoD cybersecurity vendor homepage SVG Onload Tag Hides Magecart Skimmer on 99 Stores Mass PolyShell attack wave hits 471 stores in one hour Novel WebRTC skimmer bypasses security controls at $100+ billion car maker PolyShell: unrestricted file upload in Magento and Adobe Commerce Digital skimmer hits global supermarket chain Building a faster YARA engine in pure Go Magento Developers Impersonated in Targeted GitHub Malware Operation Claude finds 353 zero-days on Packagist The billion-dollar security.txt problem Keylogger targets 200,000+ employees at major US bank ConnectPOS leaked Github secrets for years Critical backdoor found in MGT Varnish extension SessionReaper attacks have started, 3 in 5 stores still vulnerable SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025-54236) Adobe patches critical Magento admin takeover via menu injection Backdoor found in popular ecommerce components Found defunct.dat on your site? You've got a problem. You have 2 weeks left to set up CSP for your store Merchants left guessing at last-minute PCI-DSS u-turn Magento Security Release APSB25-08 [Impact Analysis] Sorry, client-side security does not work Google services abused in skimming campaigns Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns
Extortion of Magento merchants
Sansec Forensics Team · 2022-11-07 · via Sansec - experts in eCommerce security

Related: many stores are occassionally contacted by "security researchers" who claim to have found a vulnerability and want a "bounty" to disclose it. In 99% of these cases, the found issue is harmless. But it is best to ask them for details. If you are uncertain, contact us and we will assess their report for you.

Subject: Your Site Has Been Compromised

Your Site Has Been HackedY0ur Site Has Been Hacked

PLEASE FoRWARD THIS EMAIL T0 SoMEoNE IN YoUR CoMPANY WH0 iS ALLoWED To MAKE IMPORTANT DECISIoNS!

We have hacked y0ur website https://your-store.com and extracted your databases.

H0w did this happen?

0ur team has f0und a vulnerability within y0ur site that we were able t0 expl0it. After finding the vulnerability we were able t0 get your database credentials and extract your entire database and move the information t0 an offsh0re server.

What does this mean?

We will systematically g0 through a series 0f steps of t0tally damaging y0ur reputation. First y0ur database will be leaked or s0ld to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails f0und they will be e-mailed that their inf0rmati0n has been s0ld 0r leaked and your site https://your-store was at fault thusly damaging y0ur reputati0n and having angry customers/associates with whatever angry cust0mers/associates d0. Lastly any links that y0u have indexed in the search engines will be de-indexed based 0ff of blackhat techniques that we used in the past t0 de-index our targets.

How d0 i stop this?

We are willing t0 refrain from destroying your site’s reputation for a small fee. The current fee is $3000 in bitcoins (0.15 BTC).

Please send the bitcoin to the foll0wing Bitcoin address (Copy and paste as it is case sensitive):

3JjyuNhzhTppLpi9enojpNxNadNvG5xEsS

once y0u have paid we will automatically get inf0rmed that it was your payment. Please note that y0u have to make payment within 3 days after 0pening this e-mail or the database leak, e-mails dispatched, and de-index of your site WiLL start!

H0w do i get Bitcoins?

Y0u can easily buy bitcoins via several websites or even offline fr0m a Bitcoin-ATM.

What if i d0n’t pay?

if y0u decide not to pay, we will start the attack at the indicated date and uph0ld it until y0u d0, there’s n0 c0unter measure to this, you will only end up wasting more m0ney trying t0 find a s0lution. We will completely destr0y your reputati0n amongst go0gle and y0ur cust0mers.

This is n0t a h0ax, do not reply to this email, d0n’t try t0 reas0n 0r negotiate, we will n0t read any replies. 0nce y0u have paid we will st0p what we were doing and y0u will never hear from us again!

Please note that Bitcoin is an0nymous and no 0ne will find 0ut that you have complied. Finally d0n't reply as this email is unmonitored.