Sansec
sansec-research · B · active
Primary research firm for Magecart and e-commerce skimming campaigns (added 2026-05-17). Surfaced by S3 sub-agent during FunnelKit/WooCommerce active-exploitation pivot; Sansec confirmed the unauthenticated checkout-endpoint injection on FunnelKit Funnel Builder (cited in 2026-05-17 brief § 1). Industry standard for WordPress/Magento/PrestaShop skimmer disclosures. Candidate; promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live, drill=Y. CANONICAL Sansec entry (duplicate id `sansec` consolidated here). FETCH → webfetch https://sansec.io/research then drill per-article; Magecart / JS-supply-chain forensics, frequently first on CDN-compromise campaigns. Promoted candidate→active; +vulns; MEDIUM→HIGH. | 2026-07-05 admiralty audit: B, independent eCommerce-security lab, first-hand skimmer/supply-chain forensics; live and drillable. Status stays active.
Cited in 8 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 7).
- Brevo: a stolen, hardcoded Cloudflare API key let an attacker inject ClickFix malware and a WordPress backdoor plugin via a CDN-edge Worker into more than 100,000 customer sites, defeating origin-side integrity checks2026-09-18
- CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed2026-09-08
- CVE-2026-71362, Adobe Commerce and Magento Open Source: an unauthenticated attacker switches a customer session to another customer's account (CVSS 9.1), and a WAF vendor reports it is already blocking attempts2026-08-16
- WordPress supply-chain compromise via Awesome Motive's CDN backdoors ~1.2M sites2026-06-16
- Magecart family runs its skimmer out of Stripe, payload in customer metadata, stolen cards exfiltrated back through api.stripe.com2026-06-07
- CVE-2026-45247, Mirasvit Full Page Cache Warmer (Magento 2 / Adobe Commerce): unauthenticated PHP object-injection RCE, now in CISA KEV2026-06-04
- CVE-2026-10611, MISP: OTP bypass when LDAP mixed-auth and OTP enforcement are both enabled2026-06-04
- FunnelKit "Funnel Builder for WooCommerce" actively exploited as Magecart skimmer on 40,000+ WordPress stores, no CVE assigned2026-05-17