Cisco's merch store targeted by dangerous malware

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

Cisco’s official merch store has been the subject of a cybersecurity attack that may have resulted in compromised customer information, including payment card details.

A report by The Register claims suspected Russia-based attackers injected data-stealing JavaScript into the company’s merch store thanks to a flaw in Adobe's Magento platform.

Despite the potential severity of the issue, Cisco has confirmed no credentials were compromised during the attack, which it says was remediated swiftly.

Russian hackers target Cisco merch store

“A Cisco-branded merchandise website that's hosted and administered by a third-party supplier was temporarily taken offline while a security issue was addressed," the company noted.

The attackers exploited a vulnerability tracked as CVE-2024-34102, which affects Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier. Arbitrary code execution is possible through the vulnerability, which has been awarded a critical 9.8 severity score on the CVSS scale.

Although Adobe has issued a security patch, it’s believed as many as 75% of firms using Adobe’s tool have not applied the fix, including the Cisco merch store.

According to c/side security workers, the script was hosted on a domain associated with an IP address located in Russia. Moreover, the domain was registered just days before the attack, raising suspicions that it could have been a “fly-by-night operation designed for quick exploitation.”

While the attack may have been spotted early enough, it serves as a gentle reminder of the importance of maintaining up-to-date software and security patches in an increasingly digital world where cyberwarfare is becoming an escalating threat.

A Cisco spokesperson added: “Based on our investigation, the issue impacted only a limited number of site users, and those users have been notified.”

More from TechRadar Pro

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
Russian flag on a laptop
Major Russian IT service provider hit with cyberattack
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
European Space Agency hack sees official store hijacked to steal customer details
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
China
Salt Typhoon hackers used this clever technique to attack US networks
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)