e commerce2 articles
StyleSmuggler: Rust-Powered Backdoor Hits Adobe Commerce Stores via Unpatched Zero-Day
A zero-day vulnerability dubbed **StyleSmuggler** is being actively exploited in Adobe Commerce and Magento e-commerce platforms, allowing attackers to inject PHP code into Magento's template system and achieve remote code execution. The two-stage attack triggers a failed payment report to inject the code, then executes it via a payment failure email — requiring no user interaction. Successful attacks deploy a Rust-written backdoor that disguises itself as a legitimate system process and communicates with a command-and-control server, with exploitation observed since September 4; Adobe patches were expected on September 8, though it was unclear whether StyleSmuggler would be addressed.
EU hits AliExpress with €550m DSA fine for failing to stop illegal goods
The European Commission has fined AliExpress €550 million — the largest ever penalty under the Digital Services Act — for failing to adequately prevent illegal and counterfeit products from being sold on its platform. The Commission found multiple failings, including ineffective illegal product detection, poor enforcement of trader penalties, and inadequate assessment of how its recommendation systems spread dodgy goods. The fine, significantly below the maximum possible penalty of nearly $9 billion, is part of broader European efforts to regulate cheap Chinese e-commerce platforms alongside newly introduced customs fees targeting low-cost imports.