Firefox Zero-Day Was Used In Attack Against Coinbase Employees, Not Its Users

An anonymous reader writes: A recent Firefox zero-day that has made headlines across the tech news world this week was actually used in attacks against Coinbase employees, and not the company’s users. Furthermore, the attacks used not one, but two Firefox zero-days, according to Philip Martin, a member of the Coinbase security team, which reported the attacks to Mozilla. One was an RCE reported by a Google Project Zero security researcher to Mozilla in April, and the second was a sandbox escape that was spotted in the wild by the Coinbase team together with the RCE, on Monday. The question here is how an attacker managed to get hold of the details for the RCE vulnerability and use it for his attacks after the vulnerability was privately reported to Mozilla by Google. The attacker could have found the Firefox RCE on his own, he could have bribed a Mozilla/Google insider, hacked a Mozilla/Google employee and viewed details about the RCE, or hacked Mozilla’s bug tracker, like another attacker did in 2015.

Read more of this story at Slashdot.

Source:
https://news.slashdot.org/story/19/06/20/1617225/firefox-zero-day-was-used-in-attack-against-coinbase-employees-not-its-users?utm_source=rss1.0mainlinkanon&utm_medium=feed