Vulnerabilità ed exploit · Attacco ad app web
Sansec segnala sfruttamento massivo di PolyShell dal 19 marzo e scansioni da oltre 50 IP. Il malware usa WebRTC DataChannels (DTLS su UDP) per caricare payload ed aggirare CSP e il monitoraggio HTTP.
1 fonte · 26 mar
The Hacker News
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
WebRTC skimmer exploits PolyShell flaw since March 19, hitting 56.7% stores, enabling stealth data theft bypassing CSP.
originalePart of the PlainSec briefing for 2026-03-27
Every edition of this story: Store Magento Colpiti da Skimmer WebRTC che sfrutta PolyShell