惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
GbyAI
GbyAI
博客园 - 司徒正美
美团技术团队
Vercel News
Vercel News
IT之家
IT之家
U
Unit 42
Y
Y Combinator Blog
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
V
Visual Studio Blog
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
博客园 - 叶小钗
A
About on SuperTechFans
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
B
Blog RSS Feed

Sansec - experts in eCommerce security

GorgonAgora: 4,800+ fake storefronts skim cards across hundreds of impersonated brands Sansec adds support for Sylius 1 & 2 Critical vulnerability in Mirasvit Cache Warmer for Magento Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts Composer vulnerability leaks GitHub tokens, threatens PHP supply chain Over 200 PrestaShop stores expose installer, allowing full takeover ClickFix malware hits DoD cybersecurity vendor homepage SVG Onload Tag Hides Magecart Skimmer on 99 Stores Mass PolyShell attack wave hits 471 stores in one hour Novel WebRTC skimmer bypasses security controls at $100+ billion car maker PolyShell: unrestricted file upload in Magento and Adobe Commerce Digital skimmer hits global supermarket chain Building a faster YARA engine in pure Go Magento Developers Impersonated in Targeted GitHub Malware Operation Claude finds 353 zero-days on Packagist The billion-dollar security.txt problem Keylogger targets 200,000+ employees at major US bank ConnectPOS leaked Github secrets for years Critical backdoor found in MGT Varnish extension SessionReaper attacks have started, 3 in 5 stores still vulnerable SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025-54236) Backdoor found in popular ecommerce components Found defunct.dat on your site? You've got a problem. You have 2 weeks left to set up CSP for your store Merchants left guessing at last-minute PCI-DSS u-turn Magento Security Release APSB25-08 [Impact Analysis] Sorry, client-side security does not work Google services abused in skimming campaigns Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns CosmicSting attack & defense overview
Adobe patches critical Magento admin takeover via menu in...
Sansec Forensics Team · 2025-06-12 · via Sansec - experts in eCommerce security

Adobe has just released several security fixes for its Commerce (Magento) platform and one of them is critical (CVE-2025-47110). Adobe urges merchants to patch within 72 hours (highest priority).

Sansec was able to simulate a successful attack, and it is likely that cyber criminals will follow suit. Surprisingly, Adobe’s Cloud infrastructure has not yet enabled WAF protection against this vulnerability. We strongly recommend that merchants use active defenses, such as Sansec Shield, to block exploit attempts immediately, buying time for a no-stress upgrade.

Who’s at risk?

The following Magento and Adobe Commerce versions are vulnerable:

2.4.8
2.4.7-p5 and earlier
2.4.6-p10 and earlier
2.4.5-p12 and earlier
2.4.4-p13 and earlier

How does the attack work?

To make threat actors none the wiser we won’t disclose specific details. However, in general we can say that the attack builds upon last year’s CosmicSting attack and requires multiple attack stages:

  1. Use cache poisoning & stored XSS to replace the backend menu bar with malicious code
  2. Wait for an admin user to use the backend
  3. Take control of the admin session
  4. The menu bar reverts to its original state

An admin session effectively grants access to customer data, payment flows and code execution.

This attack will temporarily break the dashboard menu bar for admin users, which is clearly an indicator for an ongoing attack. However, staff may consider it a “fluke” if the menu works again after a minute or so, and not escalate it.

Sansec also found other admin blocks vulnerable to cache poisoning, such as the footer. While future attacks on these blocks can't be ruled out, they are less trivial to exploit.

Mitigation steps

Sansec Shield blocks this attack out of the box and Sansec eComscan has been updated with detection heuristics.

As general mitigation, we recommend to rotate your secret crypt key if you haven’t done so after implementing the original CosmicSting patch APSB24-40.

See also

Adobes bulletin APSB25-50 (multiple fixes) and their isolated patch for CVE-2025-47110.

Shoutout to Julian Nuß of integer_net for an insightful discussion.

Credits to blaklis for discovering CVE-2025-47110.

Read more