惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
B
Blog
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
爱范儿
爱范儿
博客园_首页
博客园 - 聂微东
量子位
V
Visual Studio Blog
aimingoo的专栏
aimingoo的专栏
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
Netflix TechBlog - Medium
F
Fortinet All Blogs
The Cloudflare Blog
T
Tailwind CSS Blog
G
Google Developers Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
腾讯CDC

Sansec - experts in eCommerce security

GorgonAgora: 4,800+ fake storefronts skim cards across hundreds of impersonated brands Sansec adds support for Sylius 1 & 2 Critical vulnerability in Mirasvit Cache Warmer for Magento Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts Composer vulnerability leaks GitHub tokens, threatens PHP supply chain Over 200 PrestaShop stores expose installer, allowing full takeover ClickFix malware hits DoD cybersecurity vendor homepage SVG Onload Tag Hides Magecart Skimmer on 99 Stores Mass PolyShell attack wave hits 471 stores in one hour Novel WebRTC skimmer bypasses security controls at $100+ billion car maker PolyShell: unrestricted file upload in Magento and Adobe Commerce Digital skimmer hits global supermarket chain Building a faster YARA engine in pure Go Magento Developers Impersonated in Targeted GitHub Malware Operation Claude finds 353 zero-days on Packagist The billion-dollar security.txt problem Keylogger targets 200,000+ employees at major US bank ConnectPOS leaked Github secrets for years Critical backdoor found in MGT Varnish extension SessionReaper attacks have started, 3 in 5 stores still vulnerable SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025-54236) Backdoor found in popular ecommerce components Found defunct.dat on your site? You've got a problem. You have 2 weeks left to set up CSP for your store Merchants left guessing at last-minute PCI-DSS u-turn Magento Security Release APSB25-08 [Impact Analysis] Sorry, client-side security does not work Google services abused in skimming campaigns Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns CosmicSting attack & defense overview
Adobe patches critical Magento admin takeover via menu in...
Sansec Forensics Team · 2025-06-12 · via Sansec - experts in eCommerce security

Adobe has just released several security fixes for its Commerce (Magento) platform and one of them is critical (CVE-2025-47110). Adobe urges merchants to patch within 72 hours (highest priority).

Sansec was able to simulate a successful attack, and it is likely that cyber criminals will follow suit. Surprisingly, Adobe’s Cloud infrastructure has not yet enabled WAF protection against this vulnerability. We strongly recommend that merchants use active defenses, such as Sansec Shield, to block exploit attempts immediately, buying time for a no-stress upgrade.

Who’s at risk?

The following Magento and Adobe Commerce versions are vulnerable:

2.4.8
2.4.7-p5 and earlier
2.4.6-p10 and earlier
2.4.5-p12 and earlier
2.4.4-p13 and earlier

How does the attack work?

To make threat actors none the wiser we won’t disclose specific details. However, in general we can say that the attack builds upon last year’s CosmicSting attack and requires multiple attack stages:

  1. Use cache poisoning & stored XSS to replace the backend menu bar with malicious code
  2. Wait for an admin user to use the backend
  3. Take control of the admin session
  4. The menu bar reverts to its original state

An admin session effectively grants access to customer data, payment flows and code execution.

This attack will temporarily break the dashboard menu bar for admin users, which is clearly an indicator for an ongoing attack. However, staff may consider it a “fluke” if the menu works again after a minute or so, and not escalate it.

Sansec also found other admin blocks vulnerable to cache poisoning, such as the footer. While future attacks on these blocks can't be ruled out, they are less trivial to exploit.

Mitigation steps

Sansec Shield blocks this attack out of the box and Sansec eComscan has been updated with detection heuristics.

As general mitigation, we recommend to rotate your secret crypt key if you haven’t done so after implementing the original CosmicSting patch APSB24-40.

See also

Adobes bulletin APSB25-50 (multiple fixes) and their isolated patch for CVE-2025-47110.

Shoutout to Julian Nuß of integer_net for an insightful discussion.

Credits to blaklis for discovering CVE-2025-47110.

Read more