Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts. We're already seeing exploitation in the wild.
Experts in ecommerce security. Helping merchants in times of peril. Tracking large scale digital skimming since 2015. PGP key 9D0D094CD2C7E669
- 🚨 SessionReaper (CVE-2025-54236) is now actively exploited while 62% of Adobe Commerce/Magento stores remain unpatched. We expect automated mass attacks within 48 hours.
- Urgent: Adobe will drop critical patch tomorrow, outside of regular patch cycle. Fixes SessionReaper attack, affects Adobe Commerce / Magento 2.3.1+. Concept patch accidentally leaked.
- 3000 stores just got hit with the "statepulseapp[.]com" skimmer, injected by Group Laski. Sansec is the only vendor that recognises it: virustotal.com/gui/domain/sta…
- 😬 More than 2000 Magento stores hacked by Peschanki group in the last 20 hours and they're not slowing down. ☞ largest automated hack of Magento stores ever ☞ 6.8% of all Adobe Commerce / Magento stores worldwide hacked via CosmicSting exploitBeware: Group Peschanki hacks over 350 new stores in the last 5 hours #cosmicsting #magento sansec.io/research/cosmi…

