2 min. reading

Massive Cyber Attacks Hit 4,200+ Magento Stores via ‘CosmicSting’ Vulnerability

Widespread attacks have an impact on thousands of online stores. A series of sophisticated cyber attacks, exploiting the CosmicSting Vulnerability, affected approximately 5% of all Adobe Commerce and Magento e-commerce platforms this summer. The breach, which affected more than 4,200 online stores, including prominent international brands ( Whirlpool and Ray-Ban), is the result of a critical security vulnerability known as CVE-2024-34102 or "CosmicSting."

This article was translated for you by artificial intelligence
Massive Cyber Attacks Hit 4,200+ Magento Stores via ‘CosmicSting’ Vulnerability
Source: Depositphotos

The Perfect Storm: Delayed Response Meets Vulnerability

A combination of factors is at the heart of this significant security breach. Adobe Commerce systems have been identified with a critical vulnerability. Numerous merchants have delayed the process of patching. Issues with the complete security of systems, even after updates have been implemented.

Adobe disclosed the vulnerability in June 2024 and released a hotfix in July, but by then, attacks were already ongoing. Automated attacks compromised cryptographic keys, which continued to be used even if stores were updated without key invalidation.

Seven hacker organizations contend for authority

Seven distinct hacker groups (like “Bobry,” “Polyovki,” and others) are competing to control these compromised stores. They use the stolen cryptographic keys to generate API tokens and insert malicious payment skimmers into checkout processes. Their attack methodology involves:

  • Utilizing the CosmicSting vulnerability to obtain confidential cryptographic keys
  • Using these keys to generate API authorization tokens
  • Obtaining confidential customer information
  • Incorporating malicious code (skimmers) into checkout processes

This competition has resulted in a peculiar situation in which multiple hacker groups repeatedly infiltrate and evict each other from the same compromised stores.

Adobe disclosed the vulnerability in June 2024 and released a hotfix in July, but by then, attacks were already ongoing. Automated attacks compromised cryptographic keys, which continued to be used even if stores were updated without key invalidation.

Source. Depositphotos

Road to Recovery

In order to mitigate this threat, cybersecurity professionals advise merchants that are affected to implement immediate measures:

  • Upgrade to the most recent version of Magento or Adobe Commerce
  • Invalidate and rotate outdated encryption keys
  • Establish resilient malware and vulnerability monitoring systems

Future Prospects: Additional Attacks on the Horizon

Sansec, a cybersecurity firm, anticipates that the number of stores affected will continue to increase, despite these recommendations. According to their research, a startling 75% of Adobe Commerce and Magento installations were unpatched when the automated attacks commenced.

This ongoing vulnerability highlights the critical importance of preventative security measures in the e-commerce sector. The sophistication and persistence of cyber threats targeting these platforms are increasing in tandem with the expansion of online retail.

Share article
Similar articles
Will ChatGPT Become OpenAI’s New Revenue Stream?
3 min. reading

Will ChatGPT Become OpenAI’s New Revenue Stream?

OpenAI is building a payment system so people can buy stuff directly through ChatGPT without leaving the chat. According to Reuters reports, merchants will pay the AI company commissions on sales. It’s a new way to make money after losing $5 billion last year despite hitting $10 billion in revenue.

Katarína Šimčíková Katarína Šimčíková
Freelance I Digital Marketing Specialist, Ecommerce Bridge EU
Marketing Teams Ignore £30 Million Problem: E-commerce Returns
4 min. reading

Marketing Teams Ignore £30 Million Problem: E-commerce Returns

Online shoppers return 30-40% more products than in-store customers, but marketing tools don’t track this data. According to analysis from The-future-of-commerce.com, one fashion brand discovered a £30 million gap between reported revenue and actual earnings after accounting for returns. Most digital marketing metrics completely miss this problem.

Katarína Šimčíková Katarína Šimčíková
Freelance I Digital Marketing Specialist, Ecommerce Bridge EU