Threat hunters warn of a sophisticated web skimming campaign that uses a deprecated API from payment processor Stripe to steal and validate payment information. Researchers believe the operation is more efficient and harder to detect. The activity, ongoing since August 2024, affects an estimated 49 merchants. The attackers likely exploit vulnerabilities in WooCommerce, WordPress, and PrestaShop, and may also be impersonating other payment forms and adding crypto payment options.

Chinese APT Group IT Service Provider Leveraging Microsoft Console Debugger to Exfiltrate Data
In early 2025, a novel campaign attributed to the Chinese APT group known as Jewelbug began targeting an IT service provider in Russia. The attackers