Firefox Zero-Day Exploited to Deliver Malware to Cryptocurrency Exchanges
#1
Quote:The recently patched Firefox vulnerability tracked as CVE-2019-11707 has been exploited to deliver Windows and Mac malware to the employees of cryptocurrency exchanges.
 
Mozilla announced on Tuesday that the latest update for Firefox patched a critical type confusion zero-day that had been exploited in targeted attacks. The Tor Project has also updated its browser, which is based on Firefox, to address the vulnerability.
 
The flaw was reported to Mozilla by the security team at cryptocurrency exchange Coinbase and Samuel Groß of Google Project Zero, but initially no details were made available on the attacks.
 
Philip Martin of the Coinbase security team revealed on Twitter that CVE-2019-11707 had been used alongside another unpatched Firefox vulnerability, a sandbox escape weakness, to target Coinbase employees. Martin said the attackers also targeted other cryptocurrency-related organizations.

SOURCE: https://www.securityweek.com/firefox-zer...-exchanges
[-] The following 2 users say Thank You to silversurfer for this post:
  • harlan4096, Mohammad.Poorya
Reply
#2
Quote:Mozilla Patches Second Firefox Zero-Day Used in Cryptocurrency Attacks
 
The flaw, tracked as CVE-2019-11708, has been described by Mozilla as a high-severity sandbox escape issue.
 
“Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer,” Mozilla said in its advisory

SOURCE: https://www.securityweek.com/mozilla-pat...cy-attacks
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Actual Microsoft Azure AZ-900 Certificat...
Our AZ-900 exam dump...jacklim — 12:35
Microsoft Releases Windows 11 Insider Bu...
Microsoft has roll...harlan4096 — 09:22
WhatsApp Is Developing On-Device Scam De...
Meta is working on...harlan4096 — 09:21
Apple Announces macOS 27 Golden Gate, Dr...
Apple announced ma...harlan4096 — 07:38
AnyDesk 9.7.5 for Windows
Version 9.7.5 for ...harlan4096 — 06:00

[-]
Birthdays
Today's Birthdays
avatar (42)zacforat
avatar (47)NemrokReks
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>