
According to Willem de Groot, founder of Sanguine Security, there has been a rapid increase in Magento 2.x e-commerce sites, which is mainly due to the action of two hacking.
Attacks on Magento 2.x sites have doubled for the 3rdconsecutive month, starting in March when the first major increase was observed.
The cause of this rapid increase in security attacks appears to be a flaw in the Magento 2.x content management system (CMS), named PRODSECBUG-2198. Magento 2.x is the most popular CMS for building automated online stores.
The flaw is an SQL injection in the Magento CMS, which can be exploited by malicious actors to gain access to an unpatched and vulnerable system.
Although Magento's security team patched the flaw in late March, this wasn't enough to keep attackers at bay, as they continued to exploit it.
To make matters worse, Ambionics, the company that discovered the bug, also published proof-of-concept code just two days after Magento was patched, without giving store owners enough time to install the patch.
As de Groot told ZDNet, while there are many groups attacking Magento stores, the recent increase seen is the result of two main hacking groups.
"There are two malicious actors that appear to be responsible," the researcher told ZDNet, "one accounts for 70% and the other for 20% of the breaches."
“The group with the highest percentage was also behind the attack on Puma Australia and 50+ other global payment services. This automation enables attackers to rapidly scale their attacks,” said de Groot.
In addition to updating Magento to versions 2.3.1, 2.2.8, and 2.1.17, which contain the fix for this security flaw, de Groot also published several tips on how to deal with hacking on a website and additional protective measures for the security of Magento stores.
