MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
coinbase
Search

Firefox Zero-Day Was Used In Attack Against Coinbase Employees, Not Its Users

Thursday June 20, 2019. 06:01 PM , from Slashdot
An anonymous reader writes: A recent Firefox zero-day that has made headlines across the tech news world this week was actually used in attacks against Coinbase employees, and not the company's users. Furthermore, the attacks used not one, but two Firefox zero-days, according to Philip Martin, a member of the Coinbase security team, which reported the attacks to Mozilla. One was an RCE reported by a Google Project Zero security researcher to Mozilla in April, and the second was a sandbox escape that was spotted in the wild by the Coinbase team together with the RCE, on Monday. The question here is how an attacker managed to get hold of the details for the RCE vulnerability and use it for his attacks after the vulnerability was privately reported to Mozilla by Google. The attacker could have found the Firefox RCE on his own, he could have bribed a Mozilla/Google insider, hacked a Mozilla/Google employee and viewed details about the RCE, or hacked Mozilla's bug tracker, like another attacker did in 2015.

Read more of this story at Slashdot.
rss.slashdot.org/~r/Slashdot/slashdot/~3/ajlMnFKJ04w/firefox-zero-day-was-used-in-attack-against-coi...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Fri 19 - 13:18 CEST