• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Fidus: vulnerability on OnePlus site permit hacker to steal sensitive credit card data
  • Data Leak

Fidus: vulnerability on OnePlus site permit hacker to steal sensitive credit card data

Ddos January 15, 2018 2 minutes read
OnePlus site

According to thenextweb, anyone who uses a credit card to buy a new OnePlus phone from the company’s official website should contact their bank immediately: Hackers could steal their money. Thenextweb reported that after a cyber-security company Fidus investigated a possible credit card fraud incident with a group of OnePlus users, it found a vulnerability that could allow a malicious agent to scan sensitive credit card data from the OnePlus Web site.

So far, hundreds of affected users have reported suspicious activity on their credit cards to the official Reddit and OnePlus forums. According to many reports, the first fraud attempt was made within a year of the user using a credit card to purchase items from the OnePlus website. Fidus said that although the attacks seem real, their research shows that the OnePlus site has not been corrupted in any way. On the contrary, it shows that the attack may come from the weakest link – Magento e-commerce platform.

Image: thenextweb

The cybersecurity expert said payments integration that had previously been hacked multiple times was often the target of malicious actors. Analysis of the payment process on the OnePlus website shows that the payment page requesting customer card details is hosted on the site, meaning that all payment details entered, though simple, can flow through the OnePlus website and can be intercepted by an attacker.

While payment details are sent to third-party providers when the form is submitted, malicious code can take advantage of one of the windows to steal credit card details before the data is encrypted. While OnePlus has not released an official statement about the incident, moderators in its forums are skeptical about the accuracy of Fidus’s research, arguing that the proposed attack vectors are not consistent with the evidence.

Reference: thenextweb

1.3/5 - (3 votes)

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Firefox browser launches Facebook Container extension to stop Facebook tracking
  2. 100GB of Secrets Seized: Akira Claims Responsibility for Nissan Cyberattack
  3. Dropbox Sign Data Breach: What You Need to Know and How to Protect Yourself
  4. Dutch DPA Fines Netflix €4.75 Million for GDPR Violations
  5. Elon Musk’s xAI Sues Ex-Engineer Over Stolen Grok AI Secrets
Tags: Fidus OnePlus site

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
  • CVE-2026-9435CVSS 9.8
    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9434CVSS 9.8
    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is...
  • CVE-2026-9433CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-2651CVSS 9.0
    A vulnerability in MLflow versions
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.