[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faw0X46JnFKLW9F2uJc0bTe3TpF5LLSdbhANvGPqYGFY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"b57c0f4d-b006-4dbd-8822-8a0ce0fdf168","webrtc-skimmer-exploits-unpatched-magento-vulnerability-to-bypass-security-controls","8068cfec-6013-4daa-ab44-c272701e5359","WebRTC Skimmer Exploits Unpatched Magento Vulnerability to Bypass Security Controls","Attackers exploited a critical Magento\u002FAdobe Commerce vulnerability (PolyShell) that allows unauthenticated code execution through REST API endpoints, with over half of vulnerable stores already compromised. The attackers deployed a sophisticated payment skimmer that uses WebRTC data channels to steal payment information while bypassing Content Security Policy protections. This attack demonstrates how unpatched vulnerabilities combined with inadequate security configurations can enable advanced threats that evade traditional detection methods.","**Immediate actions:**\n- Organizations should implement a robust vulnerability management program with regular security updates and patch deployment for all e-commerce platforms and components\n\n**Long-term improvements:**\n- Content Security Policy should be properly configured with strict directives and regularly tested against bypass techniques\n- API endpoints should have proper authentication controls and input validation\n- Regular security assessments should test for both known vulnerabilities and potential CSP bypass methods\n\n**Detection measures:**\n- Network monitoring should include inspection of WebRTC traffic and unusual UDP communications",[12,13,14,15,16,17,18],"CIS Control 7","CIS Control 11","NIST SI-2","NIST CM-6","NIST SI-4","PCI DSS 6.1","PCI DSS 6.2","published","2026-03-26T09:07:13.132231+00:00","2026-03-26T09:07:12.847+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fwebrtc-skimmer-bypasses-csp-to-steal.html","webrtc-skimmer-bypasses-csp-to-steal-payment-data-from-e-commerce-sites","WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":34,"name":35,"slug":36,"description":37,"color":38},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]