Cybercriminals are exploiting a zero-day vulnerability in Adobe Commerce and Magento, identified as "StyleSmuggler," to deploy a sophisticated Linux backdoor on e-commerce servers. The attack leverages vulnerabilities in the way the platform handles CSS and layout templates, allowing attackers to bypass security measures and gain deep access to the underlying server architecture.
Once the backdoor is established, threat actors can maintain persistent access, execute arbitrary commands, and potentially intercept sensitive customer information or payment data. Security experts recommend that Magento administrators immediately apply the latest security patches provided by Adobe and audit their systems for any unauthorized file modifications or suspicious layout templates.
Top comments (0)