Boletines de Vulnerabilidades

CSS-JS Steganography in Fake Flash Player Update Malware


Información sobre el sistema

   
Software afectado Wordpress

Descripción

This summer, MalwareBytes researcher Jérôme Segura wrote an article about how criminals use image files (.ico) to hide JavaScript credit card stealers on compromised e-commerce sites. In a tweet, Affable Kraut also reported another similar obfuscation technique using .ico files to conceal JavaScript skimmers. Just something I’ve noticed more recently with digital skimmers/#magecart. Obfuscated code […]

More info:

http://feedproxy.google.com/~r/sucuri/blog/~3/pelL3-1iX6Y/css-js-steganography-in-fake-flash-player-update-malware.html

Identificadores estándar

Propiedad Valor
CVE AL-1536X1043.

Histórico de versiones

Versión Comentario Data
1.0 Advisory issued 2020-11-04
Ministerio de Defensa
CNI
CCN
CCN-CERT