VU#614868: OpenCart ecommerce platform contains directory traversal vulnerability
OpenCart 4.2.0.0 extension installer fails to validate zip extraction paths, allowing directory traversal (CVE-2026-18412) to write files outside intended directories.
CERT/CC VU#614868 discloses CVE-2026-18412, a directory traversal vulnerability in OpenCart v4.2.0.0's extension installer. The installer extracts uploaded .ocmod.zip files using zip entry filenames as filesystem paths without verifying the resolved path stays inside the intended directory. A malicious extension zip could result in arbitrary file writes outside the target directory.
More than 100,000 fake stores are out to steal your card details
Researchers uncovered DoppelCart, a network of roughly 119,000 cloned fake shops that harvest card details and one-time bank codes during checkout.
Researchers at German firm Nebty identified 118,787 .shop domains tied to cloned online stores, representing 2.72% of the TLD population examined and described as the largest publicly documented fake-shop network by domain count. The shops mimic more than 44,000 brands, advertise discounts up to 65%, and 96% of confirmed shops reportedly share identical build files using just 27 ecommerce backends. Fraudulent checkout pages send card numbers, CVVs, billing data and bank one-time confirmation codes to attacker-controlled servers in real time over WebSockets, allowing criminals to complete payments while victims are still checking out.
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Google Threat Intelligence details BREEZE COMET, a financially motivated group manipulating Brazilian payment systems and banking software to conduct fraudulent transfers since 2024.
Mandiant and Google Threat Intelligence Group (GTIG) track this activity as BREEZE COMET (formerly UNC5669), active since 2024 against Brazilian financial services, retail, and eCommerce organizations. The actor specializes in manipulating payment systems and banking software to conduct fraudulent transfers. The activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. The report details the group's tactics, toolkit, mitigations, and detections for this active and developing threat.
Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments
Roundup: expired Visa cards can be revived for contactless payments via NFC relay; plus Apple spyware warnings and Ukraine cyberattacks on Russian e-commerce.
WIRED's weekly security roundup leads with research showing expired Visa contactless cards can be revived to make new payments through an NFC man-in-the-middle attack that alters the card's expiration date. The roundup also covers Apple sending an unprecedented volume of spyware warnings to users and Ukrainian cyber and drone attacks against a major Russian e-commerce company.