Sunday , January 26 2025
e commerce

Hackers Target E-Commerce in Bangladesh, Sell order details on Dark Web

Hackers target Bangladeshi many WordPress based e-commerce sites for their illegal activities. Getting access they are now offer to sell the taken access on the dark web. But, the alarming issue is that on those post not any specific site name has been mentioned. So, this is really difficult to realize which sites are actually been compromised.

BCSI said, a close inspection of the data indicate that Bangladeshi Cash on delivery (COD) sites and Redirect payment methods are mostly targeted by the cyber criminal. With 17,293 all-time orders, 1,206 orders in April, and 460 orders in May, these shops are prime targets due to the volume of transactions and the potential value of the data involved.

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass

An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting...
Read More
Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass

CISA Releases 6 ICS Advisories Detailing Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released 6 advisories for Industrial Control Systems (ICS), highlighting vulnerabilities in various...
Read More
CISA Releases 6 ICS Advisories Detailing Security Issues

Account Credentials for Security Vendors Found on Dark Web: Cyble Report

# "While many leaked security credentials belong to customers, some exposed sensitive accounts suggest that security vendors too have been...
Read More
Account Credentials for Security Vendors Found on Dark Web: Cyble Report

Four Critical Ivanti CSA Vulnerabilities Exploited: CISA , FBI warns

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released a joint Cybersecurity Advisory...
Read More
Four Critical Ivanti CSA Vulnerabilities Exploited: CISA , FBI warns

GitLab Releases Patch (CVE-2025-0314) for XSS Exploit

GitLab has released update for high severity cross-site scripting (XSS) flaw. Versions 17.8.1, 17.7.3, and 17.6.4 for both Community Edition...
Read More
GitLab Releases Patch  (CVE-2025-0314) for XSS Exploit

CVE-2025-20156
Cisco Fixes Meeting Management Allowing Privilege Escalation

Cisco has released a security advisory concerning a critical privilege escalation vulnerability (CVE-2025-20156) in its Meeting Management software. With a...
Read More
CVE-2025-20156  Cisco Fixes Meeting Management Allowing Privilege Escalation

Delay patching leaves about 50,000 Fortinet firewalls to zero-day attack

Fortinet customers must apply the latest updates, as almost 50,000 management interfaces remain vulnerable to the latest zero-day exploit. The...
Read More
Delay patching leaves about 50,000 Fortinet firewalls to zero-day attack

Daily Security Update Dated: 21.01.2025

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated: 21.01.2025

126 Linux kernel Vulns Allow Attackers Exploit 78 Linux Sub-Systems

Ubuntu 22.04 LTS users are advised to update their systems right away due to a crucial security patch from Canonical...
Read More
126 Linux kernel Vulns Allow Attackers Exploit 78 Linux Sub-Systems

CERT-UA alerts about “security audit” requests through AnyDesk

Attackers are pretending to be Ukraine's Computer Emergency Response Team (CERT-UA) using AnyDesk to access target computers. “Unidentified individuals are...
Read More
CERT-UA alerts about “security audit” requests through AnyDesk
    Source: BCSI

                                                  The Threat Uncovered:
For various reasons like outdated plugins, weak passwords, or other security loopholes hackers to gain control the sites. When they got access, they put it up for auction. This could result in financial losses, reputational damage, and operational disruptions.

                     Potential Risks for Bangladeshi E-Commerce:
As Bangladeshi e-commerce industry is growing up, such unauthorized access incidents pose significant risks:

Customer Data Breach:
Unauthorized access may cause sensitive customer information to be leaked. This includes personal mobile numbers, delivery addresses, email addresses, and payment information. Such a breach can seriously impact customer privacy and trust.

Financial Losses:
Cybercriminals could conduct fraudulent transactions, steal funds, or demand ransom, leading to direct financial harm to the businesses.

Reputational Damage:
If customer data is exposed, they lose trust in the platform, which can hurt business and the brand’s reputation.

Operational Disruption:
Unauthorized access can cause significant problems for businesses operations.

                 Strengthening WordPress Security:
To combat these threats,  BCSI suggested that Bangladeshi e-commerce businesses must enhance their security measures. Here are some essential steps:

Regular Updates:
Keep your WordPress core, themes, and plugins updated. These updates usually fix security issues.

Strong Passwords:
Create strong, unique passwords for each account you have. Consider using a password manager to safely keep track of these complex passwords.

Two-Factor Authentication (2FA):
Adding 2FA greatly enhances security by reducing unauthorized access risk.

Security Plugins:
Utilize security plugins for monitoring and site protection against potential threats.

Regular Backups:
Make sure to regularly back up your WordPress site. If there’s a security breach, having a recent backup can help you restore the site with minimal data loss.

Monitoring and Audits:
Regularly assess site performance and perform security checks to promptly discover and fix vulnerabilities.

Unauthorized WordPress access sales are a major issue for e-commerce businesses in Bangladesh. To protect themselves and their customers, businesses should understand the threat and take proactive security measures. It is important to stay updated on cybersecurity threats to maintain a safe online marketplace.

 

Check Also

Azure DevOps

Multiple Azure DevOps Vulns Allow To Inject CRLF Queries & Rebind DNS

Security researchers have found several vulnerabilities in Azure DevOps that could enable attackers to inject …

Leave a Reply

Your email address will not be published. Required fields are marked *