top of page
WEB SECURITY, MAGENTO, MALWARE, E-COMMERCE, INDICATORS OF COMPROMISE, CYBERSECURITY, RANSOMEWARE
Featured Articles
Discover resources and insights to help you protect your website from cyber threats. New malware detection, trend reports, website security scan tool features.


Magento & Adobe Commerce Facing Major Attack Surge: SessionReaper
Magento 2 and Adobe Commerce users are currently dealing with a critical security crisis: the SessionReaper vulnerability (CVE-2025-54236) has triggered a rapid surge in malware attacks, jumping 47% in recent weeks[1][5]. What Is SessionReaper? SessionReaper is a remote code execution flaw that lets attackers hijack user sessions and even seize full control of a store’s server - often without any authentication[1][5]. Exploitation typically involves uploading malicious sessio
Benjamin Hosack
18 hours ago2 min read


MirrorMask: a tiny code change that silently skims checkout data
At Turaco Labs, we have identified a live digital skimmer (e-skimmer) that hijacks Stripe Elements (and potentially other gateways) by proxying Stripe through a look-alike mirror system . A small and innocuous PHP code change quietly rewrites js.stripe.com to the attacker’s domain. From there, a transparent reverse-proxy spoofs headers and modifies responses while returning content that looks and behaves exactly like the real thing. While most attacks that aim to replace t
Benjamin Hosack
Aug 155 min read


Protecting Your eCommerce Business from E-Skimming Threats
Understanding Digital Skimmers / E-Skimming: The Invisible Threat to Your Business E-skimming, also referred to as digital skimming, web...

Nickola Bales
Jul 295 min read


Essential Security Steps for eCommerce Website Protection
eCommerce websites face an unprecedented level of cyber threats, with digital skimmers ThreatView - eCommerce Security and malware...

Nickola Bales
Jul 116 min read


Security First, Then PCI Compliance
A regular query we've had from our partners is "how we are going to support the new PCI requirements 6.4.3 and 11.6.1 for eCommerce...
Benjamin Hosack
Jul 93 min read


Simplifying PCI Compliance: ThreatView Now Offers Free PCI DSS Support for All Users: 6.4.3 and 11.6.1.
eCommerce businesses face an increasingly complex cybersecurity landscape, with PCI compliance requirements adding another layer of...

Nickola Bales
Jun 44 min read


Website Security Scanners - How Do They Help?
Why Your eCommerce Business Needs Website Security Scanning Peace of Mind in the Digital Marketplace While implementing a website...
Benjamin Hosack
May 123 min read


Challenging Client-Side Security Protection (PCI 6.4.3) as a "Silver Bullet"
Silver Bullet or Simply Part of a Multi-Layered Defence? With the new PCI DSS Requirement 6.4.3 for eCommerce sites, much is being said...
Benjamin Hosack
May 83 min read


ThreatView in Magento/Adobe Commerce Cloud Environments
Overview - Installation Guide for ThreatView in Magento/Adobe Commerce Cloud Environments This guide provides step-by-step instructions...
Benjamin Hosack
May 68 min read


PCI 4.0.1 - Complying with 6.4.3, 11.6.1 AND 11.5.2
Understanding PCI DSS 4.0.1 and How ThreatView Can Help What is the PCI DSS? The Payment Card Industry Data Security Standard (PCI DSS)...
Benjamin Hosack
May 14 min read


ThreatView by TuracoLabs Becomes Official Magento Association Partner
In a major step toward securing the eCommerce ecosystem, ThreatView has become an official security partner of the Magento Association.

Nickola Bales
Mar 312 min read


eCommerce Businesses: Focus on Security, PCI Compliance is a Result (6.4.3, 11.5.2, 11.6.1)
There is a great deal of interest and focus on the new PCI requirements coming into force this month for eCommerce merchants: Requirement...
Benjamin Hosack
Mar 203 min read


eCommerce PCI DSS 6.4.3 and 11.6.1
The eCommerce PCI DSS landscape is evolving, with the latest FAQ from the PCI SSC clarifying which eCommerce merchants need to complete...
Benjamin Hosack
Mar 112 min read


Annual eCommerce ThreatScape 2024
Cybercriminals are becoming more sophisticated, and eCommerce sites remain their #1 target. Our 2024 eCommerce Security Year in Review...
Benjamin Hosack
Feb 171 min read


Recovering from a Malware Infection - Simplifying File Change Monitoring - PCI DSS Requirement 11.5.2
The buzz around the new PCI DSS requirements for eCommerce is well-deserved - and for good reason. The evolving threat landscape demands...
Benjamin Hosack
Dec 3, 20242 min read


Is Your eCommerce Business Compliant with PCI DSS 6.4.3?
The eCommerce industry has been targeted by criminals with growing intensity over the last couple of years. The number of hacked sites...
Benjamin Hosack
Dec 2, 20243 min read


eCommerce Security - ThreatScape Report - October 2024
Our October 2024 eCommerce Security ThreatScape Report is ready and here are a few of the highlights: Portfolio: 16m+ websites. "Hacked...
Benjamin Hosack
Nov 11, 20242 min read


eCommerce Security - ThreatScape Report - September 2024
Our September 2024 eCommerce ThreatScape Report is ready and here are a few of the highlights: Portfolio: 16m+ websites. Slight DECREASE ...
Benjamin Hosack
Oct 15, 20241 min read


August 2024 eCommerce ThreatScape - Digital Skimmers and Loaders
The eCommerce ThreatScape Report for August 2024 showed that the industry is facing a level of attack and compromise that we have not...
Benjamin Hosack
Sep 23, 20241 min read


eCommerce Risk with Exposed Admin Login Panels
Exposed Admin Login pages are a significant security risk. Here are a few recommendations to improve security.

Nickola Bales
Aug 7, 20242 min read
bottom of page
