15 October 2024

Recently fixed Firefox zero-day abused in attacks against Tor Browser users


Recently fixed Firefox zero-day abused in attacks against Tor Browser users

A zero-day vulnerability patched by Mozilla last week was exploited in attacks targeting users of Tor Browser.

The vulnerability, tracked as CVE-2024-9680, has been described as a use-after-free bug within the Animation timeline component. Exploitation of the flaw allows attackers to execute code in the content process by manipulating animation timelines. The flaw affects Firefox and Firefox Extended Support Release (ESR) products.

Shortly after Mozilla rolled out security updates to address the flaw, the Tor Project released an emergency fix to address CVE-2024-9680. According to the maintainers, by exploiting the flaw an attacker could take control of Tor Browser. However, the team noted that the issue probably could not be abused to deanonymize users in Tails.

Last week, CISA released a security alert warning that threat actors are using unencrypted persistent cookies managed by the F5 BIG-IP Local Traffic Manager (LTM) to conduct reconnaissance on target networks. These cookies allow attackers to gather information about non-internet-facing devices, potentially identifying additional network resources for exploitation. CISA has urged organizations to encrypt cookies in F5 BIG-IP devices and use the BIG-IP iHealth diagnostic utility to identify and resolve security issues.


Back to the list

Latest Posts

Telekopye scam network expands to target tourists via hotel booking scam

Telekopye scam network expands to target tourists via hotel booking scam

ESET’s telemetry shows that the surge in the scams began in mid-2024, with a sharp increase in July.
15 October 2024
Pokémon developer confirms cyberattack and data leak

Pokémon developer confirms cyberattack and data leak

The company did not clarify whether any unreleased projects or future game details were leaked.
15 October 2024
Recently fixed Firefox zero-day abused in attacks against Tor Browser users

Recently fixed Firefox zero-day abused in attacks against Tor Browser users

By exploiting the flaw an attacker could take control of Tor Browser.
15 October 2024