1、1Entering Through the Gift Shop:Volume 9,Issue 3 SOTIState of the InternetVolume 9,Issue 31Entering Through the Gift Shop:Volume 9,Issue 3 SOTITable of Contents12Commerce at the forefront of cyberattacks3Key insights of the report4Web application and API attacks10Third-party JavaScript:A pathway to
2、supply chain attacks13The assaults on commerce consumers continue20Phishing campaigns during the holiday season23Attacks on Commerce:APJ Snapshot33Attacks on Commerce:EMEA Snapshot42Conclusion:Combating attacks against commerce43Methodology44CreditsEntering Through the Gift Shop:Volume 9,Issue 3 SOT
3、I2Entering Through the Gift Shop:Volume 9,Issue 3 SOTICommerce at the forefront of cyberattacks Commerce organizations are challenged with a complex and dynamic attack surface that continues to introduce risks,resulting in both server-side and client-side threats.Because of the nature and troves of
4、sensitive data like personally identifiable information and payment account details these organizations possess,the commerce vertical remains one of the most attacked industries and a lucrative target for cybercriminals.Compared to other industries like financial services and healthcare,commerce is
5、less heavily regulated but needs the same security maturity level.The commerce industry is characterized by a complex ecosystem of infrastructure to secure,such as point-of-sale(PoS)terminals,Internet of Things(IoT)devices,and mobile,and it leverages web applications and APIs to drive business furth
6、er.Scripts from third-party vendors are often tapped to enhance the overall customer experience and drive conversions on the commerce websites.Doing so introduces another layer of risk,as most third-party scripts use open source libraries,and attackers could exploit vulnerabilities found in them.We