
Sign up to save your podcasts
Or
Maxim Zavodchik from Akamai joins Dave to discuss their research on "Xurum: New Magento Campaign Discovered." Akamai researchers have discovered an ongoing server-side template injection campaign that is exploiting digital commerce websites. This campaign targets Magento 2 shops, and was dubbed Xurum in reference to the domain name of the attacker’s command and control (C2) server.
The research states "The attacker uses an advanced web shell named “wso-ng” that is activated only when the attacker sends the cookie “magemojo000” to the backdoor “GoogleShoppingAds” component."
The research can be found here:
Learn more about your ad choices. Visit megaphone.fm/adchoices
4.8
982982 ratings
Maxim Zavodchik from Akamai joins Dave to discuss their research on "Xurum: New Magento Campaign Discovered." Akamai researchers have discovered an ongoing server-side template injection campaign that is exploiting digital commerce websites. This campaign targets Magento 2 shops, and was dubbed Xurum in reference to the domain name of the attacker’s command and control (C2) server.
The research states "The attacker uses an advanced web shell named “wso-ng” that is activated only when the attacker sends the cookie “magemojo000” to the backdoor “GoogleShoppingAds” component."
The research can be found here:
Learn more about your ad choices. Visit megaphone.fm/adchoices
1,965 Listeners
360 Listeners
628 Listeners
367 Listeners
179 Listeners
314 Listeners
388 Listeners
927 Listeners
7,844 Listeners
165 Listeners
186 Listeners
313 Listeners
78 Listeners
118 Listeners
33 Listeners