Vulnerabilità · 190 giorni fa
Sansec segnala sfruttamento massivo di PolyShell dal 19 marzo e scansioni da oltre 50 IP. Il malware usa WebRTC DataChannels (DTLS su UDP) per caricare payload ed aggirare CSP e il monitoraggio HTTP.
1 fonte che coprono questa storia
WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
WebRTC skimmer exploits PolyShell flaw since March 19, hitting 56.7% stores, enabling stealth data theft bypassing CSP.
Part of the PlainSec briefing for 2026-03-27