Magento Patches Critical SQL Injection and RCE Vulnerabilities

Magento patched 37 flaws Thursday, including a stored cross-site scripting (XSS) vulnerability that could have let an attacker take over a site. Continue reading Magento Patches Critical SQL Injection and RCE Vulnerabilities

Critical Magento SQL Injection Vulnerability Discovered – Patch Your Sites

If your online e-commerce business is running over the Magento platform, you must pay attention to this information.

Magento yesterday released new versions of its content management software to address a total of 37 newly-discovered security vulnerab… Continue reading Critical Magento SQL Injection Vulnerability Discovered – Patch Your Sites

Adobe launches its Commerce Cloud, based on its Magento acquisition

Adobe today announced the launch of its Commerce Cloud, the newest part of the company’s Experience Cloud. Unsurprisingly, the Commerce Cloud builds on the company’s $1.68 billion acquisition of Magento last May. Indeed, at its core, the Adobe Commerce Cloud is essentially a fully managed cloud-based version of the Magento platform that is fully integrated […] Continue reading Adobe launches its Commerce Cloud, based on its Magento acquisition

Most Magento shops get compromised via vulnerable extensions

Vulnerable third party extensions (modules) are now the main source of Magento hacks, says security researcher and Magento forensics investigator Willem de Groot. “The method is straightforward: attacker uses an extension bug to hack into a Magen… Continue reading Most Magento shops get compromised via vulnerable extensions

New Windows Zero-Day Flaw Dropped on Twitter

A new vulnerability affecting Windows 10 has been disclosed on Twitter before being patched and it allows attackers to delete system files or to replace sensitive libraries. The vulnerability is located in the Windows Data Sharing Service (dssvc.dll) … Continue reading New Windows Zero-Day Flaw Dropped on Twitter

Magecart Cybergang Targets 0days in Third-Party Magento Extensions

Over two dozen third-party ecommerce plugins contain zero-day vulnerabilities being exploited in a recent Magecart campaign. Continue reading Magecart Cybergang Targets 0days in Third-Party Magento Extensions

After its acquisition, Magento starts integrating Adobe’s personalization and analytics tools

It’s been less than six months since Adobe acquired commerce platform Magento for $1.68 billion and today, at Magento’s annual conference, the company announced the first set of integrations that bring the analytics and personalization features of Adobe’s Experience Cloud to Magento’s Commerce Cloud. In many ways, the acquisition of Magento helps Adobe close the […] Continue reading After its acquisition, Magento starts integrating Adobe’s personalization and analytics tools