CAGL A.I CyberSecurity Scoring
CAGL
Company Information
Website:https://www.cmbautomotive.com
Employees number:9
Number of followers:469
NAICS:541613
Industry Type:Advertising Services
Homepage:cmbautomotive.com
CAGL Risk Score (AI oriented)
Between 700 and 749
CAGLAdvertising Services
Updated:
03/04/2026
03/04/2026
748/1000
Moderate
Ba
CAGL Global Score (TPRM)
xxxx
CAGLAdvertising Services
Score locked

CAGLModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
748
JUNE 2026
748
MAY 2026
748
APRIL 2026
748
MARCH 2026
749
Vulnerability
19 Mar 2026 • CAGL
Adobe and Unnamed Car Manufacturer: WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites
New WebRTC-Based Payment Skimmer Bypasses Security Controls in Major E-Commerce Attack
748
CRITICAL-1
ADOCMB1774536907
New WebRTC-Based Payment Skimmer Bypasses Security Controls in Major E-Commerce Attack
Cybersecurity researchers at Sansec have uncovered a sophisticated payment skimmer that leverages WebRTC data channels to exfiltrate stolen payment data, evading traditional security measures. Unlike conventional skimmers that rely on HTTP requests or image beacons, this malware establishes a peer-to-peer WebRTC connection to transmit payloads and stolen information, making detection significantly harder.
The attack targeted an e-commerce website of a car manufacturer and exploited PolyShell, a critical vulnerability in Magento Open Source and Adobe Commerce. The flaw allows unauthenticated attackers to upload arbitrary executables via the REST API, enabling remote code execution. Since March 19, 2026, the vulnerability has been massively exploited, with over 50 IP addresses scanning for vulnerable stores. Sansec reports that 56.7% of all exposed stores have already been compromised.
The skimmer operates as a self-executing script that connects to a hard-coded IP address (202.181.177[.]177) over UDP port 3479 using WebRTC. Once connected, it retrieves malicious JavaScript code, injecting it into the webpage to steal payment details. The use of DTLS-encrypted UDP traffic rather than HTTP allows the attack to bypass Content Security Policy (CSP) restrictions, rendering many network security tools ineffective.
Adobe released a beta patch (version 2.4.9-beta1) on March 10, 2026, but the fix has yet to reach production versions. While mitigations include blocking access to the *pub/media/custom_options/* directory and scanning for web shells, the attack highlights a growing trend of skimmers exploiting non-HTTP protocols to evade detection.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
749
JANUARY 2026
749
DECEMBER 2025
749
NOVEMBER 2025
749
OCTOBER 2025
749
SEPTEMBER 2025
749
AUGUST 2025
749
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CAGL ??
What was CAGL's A.I Rankiteo Cyber Score in June 2026 ??
What was CAGL's A.I Rankiteo Cyber Score in May 2026 ??
What was CAGL's A.I Rankiteo Cyber Score in April 2026 ??
What was CAGL's A.I Rankiteo Cyber Score in March 2026 ??
What was CAGL's A.I Rankiteo Cyber Score in February 2026 ??
What was CAGL's A.I Rankiteo Cyber Score in January 2026 ??
What was CAGL's A.I Rankiteo Cyber Score in December 2025 ??
What was CAGL's A.I Rankiteo Cyber Score in November 2025 ??
What was CAGL's A.I Rankiteo Cyber Score in October 2025 ??
What was CAGL's A.I Rankiteo Cyber Score in September 2025 ??
What was CAGL's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on CAGL's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CAGL ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CAGL's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?