Hackers use pixel-large SVG trick to hide credit card stealer
2026-04-09T01:23:37Z•ef4b4d768a53de2b76c4d2e878cbb845fd686ee65b3456599beb2513eec82b90
Allen-BradleyApache ActiveMQAtomic StealerBPO compromiseCISACVE-2025-59528ClickFixFlowiseIran-linked actors','FrostArmada','DNS hijack','MikroTik','TP‑LPIvanti EPMMMagentoNinja FormsPLC targetingRCERockwellSVGSaaS integrator breachSnowflakeUNC6783WordPressZendeskcredit-card theftdata theftmacOSweb skimmer
What happened
Collection of active exploitation and large-scale cybercrime trends: attackers are hiding credit-card skimming/stealers in pixel-sized SVGs on Magento stores; UNC6783 is compromising BPOs to steal corporate Zendesk support tickets; a macOS campaign uses a Script Editor ClickFix variant to deliver Atomic Stealer; CISA ordered federal patching for a critical, actively exploited Ivanti EPMM vulnerability; researchers disclosed a 13-year-old RCE in Apache ActiveMQ Classic; Flowise's maximum-severity RCE (CVE-2025-59528) is being exploited in the wild; a critical file-upload/RCE in Ninja Forms File
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- ef4b4d768a53de2b76c4d2e878cbb845fd686ee65b3456599beb2513eec82b90
- Enrichment time
- 2026-04-09T01:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.