Connect with us

WORDPRESS

Mailchimp drabbas av tredje intrång på 12 månader

Published

on

Mailchimp drabbas av tredje intrång på 12 månader

Email marketing specialist Mailchimp has suffered its third data breach arising from a social engineering attack in the space of a year, but on this occasion has won some praise for its swift and candid response to the incident.

In a statement first published on Friday 13 January, later updated on Tuesday 17 January, Mailchimp said that it first identified the breach on Wednesday 11 January. The attack saw an unauthorised party access customer support and admin tools by phishing its employees and stealing their credentials, before accessing data on 133 customers.

Mailchimp said it suspended account access for affected accounts immediately and notified its primary contacts for those accounts within 24 hours. It has since been working with them to reinstate access safely and provide needed support.

“Based on our investigation to date, this targeted incident has been limited to 133 Mailchimp accounts. There is no evidence that this compromise affected Intuit systems or customer data beyond these Mailchimp accounts,” the company said.

“We know that incidents like this can cause uncertainty, and we’re deeply sorry for any frustration. We are continuing our investigation and will be providing impacted account holders with timely and accurate information throughout the process,” said the company, which has also provided an email address for affected users to contact ([e-postskyddad]).

While Mailchimp has on this occasion moved quite quickly, the latest incident to affect it seems to maintain a pattern of internal compromise at the organisation.

In April 2022, cryptocurrency companies including Bitcoin hardware wallet maker Trezor were targeted by phishing campaigns after a threat actor breached Mailchimp. This attack was also the result of malicious access to an internal customer support tool, as confirmed by its then CISO Siobhan Smyth.

The second incident, which appears to have cost Smyth her job – she now works as CIO at a US-based healthcare company – unfolded in August 2022, also targeted organisations working in the crypto sector that were customers of DigitalOcean, a specialist in cloud infrastructure services. DigitalOcean, which ditched Mailchimp following the attack, said that it understood this attack had also been the result of an attacker compromising Mailchimp’s internal tools.

Ultimately, this attack was deemed to be the work of Scatter Swine, aka 0ktapus, a highly successful campaign of supply chain compromises that exploited the branding of identity and access management (IAM) specialist Okta. Somewhat ironically, Okta’s subsequent investigation revealed evidence that the group was using infrastructure provided by a provider called Bitlaunch, which itself used DigitalOcean’s services.

Eset global cyber security advisor Jake Moore said that the incident was highly worrying: “2023 is shaping up to be the year that attackers don’t hack in, they log in. Social engineering hacks targeting third-party tools are becoming more prevalent and sophisticated, and in recent months we have seen some big names being targeted with huge results,” he said.

“Although this may only seem like a very small number of customers that have had details compromised, this is still a very worrying breach of data…No doubt attempts would have been made to siphon more data than was stolen, but this will still land as an embarrassment for the company which is known for storing large amounts of client data along with their client’s personally identifiable information.”

ImmuniWeb founder Ilia Kolochenko said: “The unauthorised access to 133 customer accounts is a very insignificant security incident for such a large company as Mailchimp.

“Transparent disclosure of the incident rather evidences a well-established DFIR process and high standards of ethics at Mailchimp, as most businesses of similar size will likely try to find a valid excuse to avoid mandatory disclosure prescribed by law or imposed by contractual duties.”

Kolochenko added that the supposed attack vector was an exceedingly efficient one, claiming multiple victims all the time, with even the best multi-layered defences and advanced controls frequently ineffective against an honest mistake. He said Mailchimp had clearly detected and contained the problem quickly, given the customer support agent or agents compromised would have certainly had access to the data of many more customers.

One organisation known to have been affected in the latest attack is WooCommerce, an open source e-commerce platform used by independent micro retailers, which notified its customers shortly after.

In a copy of the notification email shared via Twitter, WooCommerce said it understood the breach may have resulted in some information, such as customer names, store URLs, and postal and email addresses exposed, but no payment data or passwords.

“There is no indication the person who engaged in unauthorised access to Mailchimp has taken any action with the exposed information,” the company said.

“We have confirmed with Mailchimp that our account is secure and follows all security best practices, and are working with them to better understand the cause of this breach and what they’re doing to prevent similar incidents in the future. We apologise for any issues or concerns this may have caused.”



Källlänk

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address

WORDPRESS

Kreditkortsstjälare riktar sig till WordPress-betalningsplugin-program

Published

on

Kreditkortsstjälare riktar sig till WordPress-betalningsplugin-program

Card Not Present Fraud
,
Fraud Management & Cybercrime

MageCart Operators Hide Infection in Legitimate Payment Processing Software

Image: Shutterstock

Hackers have repurposed credit card-stealing malware to attack WordPress websites that use a popular e-commerce plug-in to capture and steal payment card details, security researches warn.

See Also: LIVE Webinar | Stop, Drop (a Table) & Roll: An SQL Highlight Discussion

Attackers are deploying modified MageCart malware against WordPress websites that use the WooCommerce shopping cart plug-in, says website security firm Sucuri. WordPress plug-in developers Barn2 calculate that more than 40% of “all known online stores” use the plug-in.

An “overwhelming majority” of credit card-skimming malware that Sucuri finds on compromised e-commerce environments target WooCommerce. The modified MageCart injects PHP code into a plug-in file that facilitates the handling of payment data to Authorize.net, a popular Visa-owned payment gateway often used in conjunction with WooCommerce. The injected code checks whether web traffic from infected websites contains a string for payment card numbers. If it does, it dumps an encrypted copy of the card number into a .jpg file for later downloading.

“Dumping stolen credit card info to an image file is an old trick that we have identified attackers doing for quite a few years,” Sucuri writes.

The vulnerabilities in question don’t originate with WooCommerce or Authorize.net, Sucuri says, and instead highlight the importance of good website security.

The modified MageCart malware also injects JavaScript into the payment gateway code to capture data such as cardholder name, address, phone number and postal code – data that increases the value of stolen payment card data on the black market.

The malware emulates the WordPress Heartbeat API to evade detection, Sucuri says.
MageCart derives its name from its original target, the Magento e-commerce platform. Hackers have used it to breach British Airways, unsecured Amazon Web Services cloud storage accounts and jewelry chain Claire’s.

Sucuri says it found the modified MageCart malware after a client received a warning from their bank that their website had been identified as potentially compromised since cards used legitimately on the client website had later been used fraudulently.

“If malicious actors compromise an environment they can tamper with existing controls,” irrespective of a plug-in’s security controls, Sucuri says.



Källlänk

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address
Continue Reading

WORDPRESS

WordPress force uppdaterar tusentals webbplatser efter WooCommerce-säkerhetsbrott

Published

on

WooCommerce skyltfönster

Top website builder (öppnas i ny flik) WordPress has pushed an urgent update to users with the WooCommerce add-on installed in response to a highly disruptive security vulnerability.

Cybersecurity researchers from GoldNetwork recently discovered a major flaw affecting WooCommerce Payments 4.8.0 and higher. WooCommerce is an open-source ecommerce WordPress plugin designed to service small and medium-sized businesses.

Källlänk

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address
Continue Reading

WORDPRESS

Bluehost lanserar nya handelslösningar för WordPress – ThePrint –

Published

on

Mumbai (Maharashtra) [India], March 24 (ANI/PRNewswire): Bluehost, one of the largest WordPress hosting providers in the world, today announced the launch of its new commerce solutions that make it simple for customers to launch their online stores and makes using WordPress easier by bringing together YITH plugins and WooCommerce. Addressing the need for a simple, convenient online selling solution for all, Bluehost’s new commerce solutions, bring together the power of WordPress, the versatility of WooCommerce and the elegant simplicity of YITH plugins to empower users to easily create online stores that truly stand out from the rest.

From a mobile-responsive eCommerce website to powerful connections with all the major online marketplaces, Bluehost’s commerce solutions enable users to sell products anywhere and everywhere confidently. The affordable all-in-one commerce solutions allow users to build a robust online store. Users can easily accept payments, sell across popular marketplaces, schedule calendar appointments, ship new customer orders, print labels, and add advanced features like GiftCards, WishList, Customer Account Page, and more. Site owners will save time and energy maintaining every aspect of their eCommerce business, all from one platform.

Bluehost’s commerce solutions make selling online easier and save customers hundreds of dollars by bundling enhanced plugins.

“We have so many customers around the world with unique needs and different levels of expertise building online stores,” said Ed Jay, President of Newfold Digital, the parent company of Bluehost and YITH. “With the launch of Bluehost’s new commerce solutions, our team is addressing the needs of small businesses looking for the flexibility and power of WordPress but want the experience of coming online and selling to be simple. The curated experience we are providing strikes the perfect balance of security, reliability, and functionality by taking the power of WordPress and putting it into the hands of users in a way that feels intuitive and native for each of our customers seeking to grow their businesses.”

Bluehost’s commerce solutions offer the functionality, and the perfect mix of tools, plugins and guidance online sellers need to start and grow their online business including:

– Easy Online Store Creation: Bluehost’s new commerce solutions come with an easy-to-follow onboarding experience. Answer a few simple questions and within minutes users will have the right foundation pages to launch their site. The guided onboarding experiences walks users through the set-up process for commonly needed features of an online store, like payment processing, tax information, shipping and managing product inventory. It helps customers launch further, faster by setting up their theme, fonts, top menu and homepage by assembling a custom design in a few simple steps.

– WooCommerce and Enhanced YITH Plugins: Both of Bluehost’s commerce solutions come with WooCommerce and enhanced YITH plugins. YITH is one of the largest sellers and developers of WooCommerce Plugins for WordPress, with nearly 2.3M active installs and more than 100 plugins that expertly solve critical eCommerce needs. Payment Processing, Gift Cards, Wish Lists, Appointment Bookings, Shipping, Product Search/Filtering and Customer Account Creation are included, providing users with everything they need to build an online store for a simple low price.

– Sales Across Multiple Marketplaces: Whether users are selling on Amazon, Etsy, eBay, Shopify, BigCommerce, or any other kind of marketplace, the Bluehost Online Store + Marketplace plan allows customers to manage their inventory from one centralized dashboard. This allows them to analyze which marketplace is the best place for selling their products, as well as keep track of inventory in real-time without having to log into multiple dashboards.

– Yoast SEO: The #1 WordPress SEO Plugin powering more than 13 million websites. Yoast SEO is made by world-renowned SEO experts and is packed full of features, designed to help visitors and search engines to get the most out of their website. Newfold acquired Yoast in August 2021.

– New WordPress eCommerce Block Theme “Wonder” Pre-installed: Take advantage of WordPress’s Block Editor with Wonder’s 24 patterns, focused on shops, and six different style variations. YITH, a leading global provider of WooCommerce plugins acquired by Newfold in March 2022, built Wonder leveraging their WordPress commerce expertise.

– Professional Services and 24/7 Expert Support: In-house Bluehost experts are readily available to help customers get online and support customers if roadblocks are encountered while creating an online store, via online chat or over the phone at 1800-419-4426.

For more information on Bluehost’s commerce solutions, including product features and details, visit Bluehost.in.

Bluehost is the leading web hosting solutions provider specializing in WordPress. Since its founding in 2003, Bluehost has been trusted by millions of people because it makes building, growing, and managing successful WordPress websites easy. Bluehost delivers a suite of WordPress solutions designed with the perfect mix of guidance, tools, and expertise to build a professional website. Bluehost is a part of the Newfold Digital family of brands. For more information on Bluehost, visit Bluehost.in.

Newfold Digital is a leading web and commerce technology company serving nearly 7 million customers globally. Established in 2021 through the combination of leading web services providers Endurance Web Presence and Web.com Group, our portfolio of brands includes: Bluehost, CrazyDomains, HostGator, Network Solutions, Register.com, Web.com, Yoast, YITH, and many others. We help customers of all sizes build a digital presence that delivers results. With our extensive product offerings and personalized support, we take pride in collaborating with our customers to serve their online presence needs. Learn more about Newfold Digital at Newfold.com.

Media Contact:

Paola Lorenzo

[email protected]

This story has been provided by PRNewswire. ANI will not be responsible in any way for the content of this article. (ANI/PRNewswire)

This story is auto-generated from a syndicated feed. ThePrint holds no responsibility for its content.

Källlänk

Keep an eye on what we are doing
Be the first to get latest updates and exclusive content straight to your email inbox.
We promise not to spam you. You can unsubscribe at any time.
Invalid email address
Continue Reading

Trendigt