Vulnerabilities & Exploits · Web App Attack
Researchers report mass exploitation since March 19, with scans from over 50 IPs and infections on 56.7% of vulnerable stores.
1 source · Mar 26
The Hacker News
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
WebRTC skimmer exploits PolyShell flaw since March 19, hitting 56.7% stores, enabling stealth data theft bypassing CSP.
originalPart of the PlainSec briefing for 2026-03-26
Every edition of this story: Magento Stores Hit by WebRTC Payment Skimmer Exploiting PolyShell