// Hacking NEWS // Mozilla Updates Firefox To Fix a New Zero-Day Flaw

in #news5 years ago

The Firefox web browser has just been updated to version 67.0.4 after the discovery of a new zero-day vulnerability linked to the first one.

aaaa.jpg

Two days after publishing an update fixing a zero-day flaw, Mozilla once again invites Firefox users to update their browser after discovering a second zero-day flaw, directly related to the first.

Two combined vulnerabilities

The previous security breach allowed hackers to remotely execute arbitrary code in targeted attacks. Since the correction of this first breach, Mozilla has discovered a second breach, directly related to the first.

While the first one allowed malicious code to be executed within the browser's processes, the second one opened the door directly to the operating system.

In its release note, Mozilla states that this new vulnerability allowed hackers to exit the Firefox sandbox, a secure space isolated from the rest of the machine, to execute malicious code on the user's OS.

Cryptocurrencies still targeted

These two zero-day vulnerabilities were mainly targeted at Coinbase employees. They received suspicious emails containing a malicious link that, if clicked on, allowed hackers to siphon data from the machine and collect passwords stored in the browser.

If the operation was successful, hackers could then enter the Coinbase system using recovered passwords to steal digital currencies.

"On Monday, Coinbase detected & blocked an attempt by an attacker to leverage the reported 0-day, along with a separate 0-day Firefox sandbox escape, to target Coinbase employees," Philip Martin said, a member of the Coinbase security team.

Source: ZDNet, Mozilla

Stay Informed, Stay Safe

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Coin Marketplace

STEEM 0.16
TRX 0.16
JST 0.030
BTC 58474.85
ETH 2500.10
USDT 1.00
SBD 2.39