Tech

Firefox and Windows zero-day security bugs hit by Russian hackers, so be on your guard

Share
Share


  • ESET discovers two zero-day vulnerabilities that can lead to remote code execution
  • The researchers spot Russian hackers abusing the flaws to deploy backdoors
  • Fixes for both flaws are already available to download

A Russian advanced persistent threat (APT) group known as RomCom has been exploiting two zero-day vulnerabilities to hit its victims with potent backdoor malware, security experts have said.

ESET said its researchers first found a use-after-free bug in the animation timeline feature in Firefox. Since the bug forces the browser to use memory that has already been freed, it can lead to all sorts of undefined behavior, including executing code in the restricted context of the browser. This bug was discovered on October 8, and was assigned CVE-2024-9680. It was fixed a day later, on October 9.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Is using AI tools innovation or exploitation? Three ways to think about the ethics
Tech

Is using AI tools innovation or exploitation? Three ways to think about the ethics

Credit: CC0 Public Domain Artificial intelligence can be used in countless ways—and...

Using AI to turn sound recordings into accurate street images
Tech

Using AI to turn sound recordings into accurate street images

Credit: University of Texas at Austin Using generative artificial intelligence, a team...

Rogue VPN servers used to spread malware via malicious updates
Tech

Rogue VPN servers used to spread malware via malicious updates

Researchers from AmberWolf find two flaws in popular VPN products Flaws can...

Addressing energy inequities in clean energy transitions
Tech

Addressing energy inequities in clean energy transitions

Concentration curve of disposable income and energy consumption, cost and burden. Credit:...