Sign in

Sansec BV

@sans.ec
198 followers 7 following 13 posts

experts in eCommerce security - sansec.io

PostsRepliesMedia
Sansec BV @sans.ec · 08/09/2025
Adobe will release fix for the critical SessionReaper attack tomorrow Sept 9th. All Magento and Adobe Commerce versions are vulnerable. Sansec Shield users are already protected, all others should standby and implement patch once it is published (likely 14h UTC). sansec.io/research/ses...
sansec.io
SessionReaper, a critical bug in Magento & Adobe Commerce (CVE-2025-54236)
Adobe breaks their regular patch schedule and will release an emergency fix for CVE-2025-54236 within the next 24 hours. Automated abuse is expected and merc...
002
Sansec BV @sans.ec · 06/06/2025
Thanks for pointing out our sampling bias, since the last graph we've stopped crawling some smaller stores but not Magento so we cannot give you an accurate distribution right now, only a relative malware activity graph for all platforms
010
Reposted by Sansec BV
BleepingComputer @bleepingcomputer.com · 02/05/2025
A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational.
bleepingcomputer.com
Magento supply chain attack compromises hundreds of e-stores
A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce stores, including one belonging to a $40 billion multinational.
084
Sansec BV @sans.ec · 02/05/2025
Coordinated supply chain attack hits 3 vendors, backdoors go unnoticed for 6 years. Sansec discovered actual abuse has started last week. sansec.io/research/lic...
sansec.io
Backdoor found in popular ecommerce components
Multiple vendors were hacked in a coordinated supply chain attack, Sansec found 21 applications with the same backdoor. Curiously, the malware was injected 6...
085
Sansec BV @sans.ec · 18/04/2025
010
Sansec BV @sans.ec · 18/04/2025
Meanwhile, the attacker has upgraded their malware and rotated three exfil domains: bootrow\.com redtransfer\.net imgweb\.net PSA — This breach would have been prevented with Sansec Shield, our real-time malware protection layer.
110
Sansec BV @sans.ec · 18/04/2025
⚽️🔥 AS Roma has been hacked since March 19. Attack is ongoing, and customer data is leaked to the Russian SmartApe network (AS62212). We reached out 5 times to their privacy & security teams but no response.
110
Sansec BV @sans.ec · 03/04/2025
Found "defunct.dat" or "qfile" on your site? They contain access keys for hidden GSocket backdoors. Mass scans for these files launched since Mar 31st. Dozens of sites affected. sansec.io/research/gso...
020
Sansec BV @sans.ec · 21/03/2025
Pro-tip: install Sansec Shield sansec.io/guides/sanse...
sansec.io
Sansec Shield
Advanced real-time protection for your Magento store
010
Sansec BV @sans.ec · 13/02/2025
Worried about having to roll out ABSP25-08 before the weekend? No stress! 🚀 Meet Sansec Shield (beta)—an origin-bound WAF built to guard your store against all major Magento attack vectors, including this week's CVSS 9.4 threat. Installation is just a composer require. sansec.io/guides/sanse...
sansec.io
Sansec Shield (Beta)
Advanced real-time protection for your Magento store
021
Sansec BV @sans.ec · 13/02/2025
Impact analysis for Adobe Commerce & Magento security release APSB25-08: unauthorized attackers can take control of your customer accounts. Not as critical as CosmicSting but still recommended to patch asap. Full analysis: sansec.io/research/mag...
sansec.io
Magento Security Release APSB25-08 [Impact Analysis]
Critical (CVSS 9.4) release enables attackers to take control of customer accounts.
001
Sansec BV @sans.ec · 23/12/2024
The exfil domain "esaspaceshop[.]pics" that is used to steal data from ESA staff, was registered a month ago but only showed up on the ESA site today.
020
Sansec BV @sans.ec · 23/12/2024
"Foreign espionage campaign launched via Christmas sweaters" The 🚀 ESA (European Space Agency) store just got hacked. The store seems to be integrated with ESA systems, as employees are required to login with their ESA email address.
196
Sansec BV @sans.ec · 19/11/2024
Welcome to our new humble presence! To commemorate, we have just released eComscan 1.7.0 with more detailed malware reporting and tons of improvements. Your version will auto upgrade. sansec.io/guides/chang...
030