Hackers use pixel-large SVG trick to hide credit card stealer

2026-04-09T01:23:37Zef4b4d768a53de2b76c4d2e878cbb845fd686ee65b3456599beb2513eec82b90
Allen-BradleyApache ActiveMQAtomic StealerBPO compromiseCISACVE-2025-59528ClickFixFlowiseIran-linked actors','FrostArmada','DNS hijack','MikroTik','TP‑LPIvanti EPMMMagentoNinja FormsPLC targetingRCERockwellSVGSaaS integrator breachSnowflakeUNC6783WordPressZendeskcredit-card theftdata theftmacOSweb skimmer

What happened

Collection of active exploitation and large-scale cybercrime trends: attackers are hiding credit-card skimming/stealers in pixel-sized SVGs on Magento stores; UNC6783 is compromising BPOs to steal corporate Zendesk support tickets; a macOS campaign uses a Script Editor ClickFix variant to deliver Atomic Stealer; CISA ordered federal patching for a critical, actively exploited Ivanti EPMM vulnerability; researchers disclosed a 13-year-old RCE in Apache ActiveMQ Classic; Flowise's maximum-severity RCE (CVE-2025-59528) is being exploited in the wild; a critical file-upload/RCE in Ninja Forms File

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
ef4b4d768a53de2b76c4d2e878cbb845fd686ee65b3456599beb2513eec82b90
Enrichment time
2026-04-09T01:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.