Sansec
sansec-research · B · active
Primary research firm for Magecart and e-commerce skimming campaigns (added 2026-05-17). Surfaced by S3 sub-agent during FunnelKit/WooCommerce active-exploitation pivot; Sansec confirmed the unauthenticated checkout-endpoint injection on FunnelKit Funnel Builder (cited in 2026-05-17 brief § 1). Industry standard for WordPress/Magento/PrestaShop skimmer disclosures. Candidate — promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live, drill=Y. CANONICAL Sansec entry (duplicate id `sansec` consolidated here). FETCH → webfetch https://sansec.io/research then drill per-article; Magecart / JS-supply-chain forensics, frequently first on CDN-compromise campaigns. Promoted candidate→active; +vulns; MEDIUM→HIGH. | 2026-07-05 admiralty audit: B — independent eCommerce-security lab, first-hand skimmer/supply-chain forensics; live and drillable. Status stays active.
Cited in 8 entries
Citation cadence
Citation days per ISO week (7 weeks of coverage span, total 7).
- Technology & SaaS supply chain — the week's busiest victim class2026-06-22
- WordPress supply-chain compromise via Awesome Motive's CDN backdoors ~1.2M sites2026-06-16
- Magecart family runs its skimmer out of Stripe — payload in customer metadata, stolen cards exfiltrated back through api.stripe.com2026-06-07
- CVE-2026-45247 — Mirasvit Full Page Cache Warmer (Magento 2 / Adobe Commerce): unauthenticated PHP object-injection RCE, now in CISA KEV2026-06-04
- CVE-2026-10611 — MISP: OTP bypass when LDAP mixed-auth and OTP enforcement are both enabled2026-06-04
- Finance / payments — Stripe-abusing Magecart and OFAC Iran sanctions2026-06-01
- FunnelKit "Funnel Builder for WooCommerce" actively exploited as Magecart skimmer on 40,000+ WordPress stores — no CVE assigned2026-05-17
- WordPress retail / e-commerce2026-05-11