Supply-Chain Attacks: Securing Shop Dependencies
Mini Shai-Hulud arrived via patch versions: 1,055 versions, 502 packages, no CVE. How to secure lockfiles, install scripts, registry mirrors and tokens.
Shops process payment and customer data and are permanently exposed on the internet — they are scanned automatically for known weaknesses. This category covers day-to-day protection: applying security updates promptly, hardening server and application, access protection with strong methods and two-factor authentication, permissions for editors and service providers, protection against bot attacks on login and checkout, and detection of malicious code. Added to this is preparation and procedure in an emergency: verifying backups, documenting incidents, knowing reporting duties, resetting credentials. We describe measures that can be sustained with reasonable effort and deliberately avoid promises of absolute security. We additionally cover which traces an attack leaves and how to tell whether an incident is closed or merely paused.
Mini Shai-Hulud arrived via patch versions: 1,055 versions, 502 packages, no CVE. How to secure lockfiles, install scripts, registry mirrors and tokens.
Security headers like CSP and HSTS are not a one-time setup. Introduce them in report-only mode, harden to enforce and keep them stable across updates.
Web skimming steals card data right in the browser. See how a script inventory, Subresource Integrity, CSP and tamper detection per PCI DSS 4.0 stop the attack.
In 2026 the patch window has shrunk to a median of 5 hours. Why no self-maintained shop keeps up manually and how managed maintenance patches automatically.
WAF and bot management as part of maintenance: how to protect your shop against automated attacks, scraping and fake traffic in live operation.
Security patch and CVE management for online shops: detect vulnerabilities, prioritize by risk, test on staging and deploy patches in a controlled way.
Detect and remove skimmers, injected scripts and backdoors: file integrity monitoring, structured cleanup and post-incident hardening for online shops.
PHP configuration, web server, file permissions, security headers and least privilege: how to harden your online shop server step by step, layer by layer.
Reconcile GDPR and backups: legal basis, retention periods, deletion concept, right to erasure, encryption, data processing agreements and EU storage location.
Compromised credentials are behind most attacks. Secure your shop backend with MFA, least-privilege roles and login defense that holds across updates.
Since 03/2025, PCI DSS 4.0.1 requires a script inventory (6.4.3) and weekly tamper detection (11.6.1) on payment pages. How to prove it with evidence.