Tech

Firefox and Windows zero-day security bugs hit by Russian hackers, so be on your guard

Share
Share


  • ESET discovers two zero-day vulnerabilities that can lead to remote code execution
  • The researchers spot Russian hackers abusing the flaws to deploy backdoors
  • Fixes for both flaws are already available to download

A Russian advanced persistent threat (APT) group known as RomCom has been exploiting two zero-day vulnerabilities to hit its victims with potent backdoor malware, security experts have said.

ESET said its researchers first found a use-after-free bug in the animation timeline feature in Firefox. Since the bug forces the browser to use memory that has already been freed, it can lead to all sorts of undefined behavior, including executing code in the restricted context of the browser. This bug was discovered on October 8, and was assigned CVE-2024-9680. It was fixed a day later, on October 9.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Study is first to use VR to understand pedestrian stress
Tech

Study is first to use VR to understand pedestrian stress

A view of the simulated environments in VR. Credit: Transportation Research Part...

Hackers are hitting firewalls and VPNs to breach businesses
Tech

Hackers are hitting firewalls and VPNs to breach businesses

Network edge devices make up nearly 30% of intrusion points Ransomware is...

Difficult and costly energy transition projected by experts unless EU invests in biomass
Tech

Difficult and costly energy transition projected by experts unless EU invests in biomass

An overview of biomass-, electricity- and fossil-based options to fulfill demands for...

The second pair of open earbuds with Bose tech are coming, but not from Bose
Tech

The second pair of open earbuds with Bose tech are coming, but not from Bose

Motorola is planning to launch open earbuds and a new watch The...