The HexMage Magecart campaign has compromised more than 40 e-commerce storefronts across at least 15 countries, primarily targeting WooCommerce sites but also affecting PrestaShop, Magento, and standard WordPress installations. Attackers first compromise the merchant’s server and inject a lightweight JavaScript loader into checkout pages, disguising it as a fake Google Tag Manager block. The loader uses Ethereum’s Sepolia testnet and attacker-controlled smart contracts to retrieve the hostname of the final payment-skimming script. The campaign uses EtherHiding, allowing malicious infrastructure to be stored and dynamically updated through blockchain smart contracts. The final skimmer captures payment-card numbers, expiry dates, CVVs, cardholder names, billing emails, and other checkout information before encoding and exfiltrating it. The malware is customized for multiple payment gateways, including Stripe, PayPal, ePay, PhonePe, and HyperPay. Researchers identified 156 related smart contracts associated with the attacker wallet by August 23, 2026. Organizations should inspect checkout pages for unauthorized JavaScript, Web3 libraries, Ethereum RPC connections, and fake GTM code. Website servers, administrator accounts, plugins, and payment templates should also be audited for compromise. Strong Content Security Policy controls should restrict unapproved scripts and outbound connections, while continuous monitoring should detect unexpected changes to checkout code. Since the article does not identify a specific CVE, CVE-IDs are not applicable/mentioned for this campaign.
Attackers have chained two vulnerabilities in JFrog Artifactory to gain administrator control of self-hosted servers and install backdoors, according to cloud security company Wiz....
Trezor has disclosed that a phishing campaign following a September 9, 2026 security incident at its third-party email marketing provider, Brevo, exposed approximately 347,000 opt-...
Microsoft’s September 2026 security updates have been associated with a serious Remote Desktop Services (RDS) stability issue affecting Windows Server 2019, 2022, and 2025. Admin...