logoalt Hacker News

hnsrtoday at 6:10 AM1 replyview on HN

Can confirm.

I work at an e-commerce agency where we work with (among others) Adobe Commerce.

The number of unauthorized RCE vulnerabilities being reported not only in the core product, but also very popular modules used in the community[1] is going through the roof.

And we are having a lot of close calls, too; just last weekend, a 0day[2] was widely being exploited at a large scale, before any publication or patch. We have learnt to be on the ball with applying patches and security updates, and even with all that effort, we saw a few projects already being hit by the initial log poisoning. We got lucky that nothing was fully compromised but I am sure that many, many webshops got infected last weekend. And not even a day later there are already other variants of this exploit showing up.

[1] https://sansec.io/research/amasty-mass-disclosure

[2] https://sansec.io/research/stylesmuggler-0day


Replies

hypfertoday at 6:34 AM

To be fair, ecommerce isn't exactly the branch of software where you get an oversupply of excited enthusiasts caring about the craft itself.

Probably a lot more "coding as a job" and "as a job" also implies "not my department".

So it's not necessarily the LLMs being very good, but might also "just" be that the software is very bad.

show 1 reply