A threat campaign is relying on cross-site scripting attacks to deliver malware to and steal credentials from online shops.
The Lazarus threat group utilized a modified JavaScript sniffer to steal cryptocurrency from unsuspecting e-commerce website consumers.
The prolific Magecart group continues to evolve its attack techniques as it uses new skimmer code to steal payment card numbers from the websites of small- and medium-sized businesses, RiskIQ researchers found.
One of the prominent Magecart threat groups, Magecart Group 5 (MG5) appears to be trying to compromise the routers used by airports, cafes, and other public buildings to provide users with public WiFi.