BigCommerce Warns Merchants of Breach via Third-Party Ribon Apps
Compromised credentials for third-party Ribon applications allowed attackers to inject malicious scripts into BigCommerce online stores.
BigCommerce has notified multiple merchants of a data breach after attackers compromised credentials belonging to third-party Ribon applications. The ecommerce platform said the attackers used those stolen credentials to inject malicious scripts into online stores.
The breach appears to have originated with the third-party apps rather than BigCommerce's own platform. Merchants using Ribon applications were the ones affected, and BigCommerce moved to alert them directly.
Because the source is a single report, there is no independent account of the incident yet. The report does not indicate whether other third-party apps were involved or how many merchants received alerts.
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.