Firefox Zero-Day Exploited to Deliver Malware to Cryptocurrency Exchanges
#1
Quote:The recently patched Firefox vulnerability tracked as CVE-2019-11707 has been exploited to deliver Windows and Mac malware to the employees of cryptocurrency exchanges.
 
Mozilla announced on Tuesday that the latest update for Firefox patched a critical type confusion zero-day that had been exploited in targeted attacks. The Tor Project has also updated its browser, which is based on Firefox, to address the vulnerability.
 
The flaw was reported to Mozilla by the security team at cryptocurrency exchange Coinbase and Samuel Groß of Google Project Zero, but initially no details were made available on the attacks.
 
Philip Martin of the Coinbase security team revealed on Twitter that CVE-2019-11707 had been used alongside another unpatched Firefox vulnerability, a sandbox escape weakness, to target Coinbase employees. Martin said the attackers also targeted other cryptocurrency-related organizations.

SOURCE: https://www.securityweek.com/firefox-zer...-exchanges
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Mohammad.Poorya
Reply
#2
Quote:Mozilla Patches Second Firefox Zero-Day Used in Cryptocurrency Attacks
 
The flaw, tracked as CVE-2019-11708, has been described by Mozilla as a high-severity sandbox escape issue.
 
“Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer,” Mozilla said in its advisory

SOURCE: https://www.securityweek.com/mozilla-pat...cy-attacks
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Linux 7.0 merges AMDGPU update for decad...
All thanks to Valv...harlan4096 — 17:55
AdGuard for iOS v4.5.16
AdGuard for iOS v4...harlan4096 — 07:24
QOwnNotes
26.2.9  Fixed a v...Kool — 05:38
AdGuard for Android 4.12.3
AdGuard for Androi...harlan4096 — 17:18
Replit Pro – One Month Free
Replit Pro     C...hanso — 17:02

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (46)dimaWeami
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>