RomCom exploits Firefox and Windows zero days in the wild

ESET Research details the analysis of a previously unknown vulnerability in Mozilla products exploited in the wild and another previously unknown Microsoft Windows vulnerability, combined in a zero-click exploit.

CVE Alert: CVE-2024-9680 - RedPacket Security

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this

RedPacket Security
Mozilla fixes critical Firefox bug exploited in the wild

Mozilla has patched a serious security flaw in its Firefox web browser that the company said is being exploited by hackers.

#TorBrowser users should update their browser immediately as they're also affected by the #CVE_2024_9680 #useafterfree #vulnerability - https://forum.torproject.org/t/new-release-tor-browser-13-5-7/15087
New Release: Tor Browser 13.5.7

by morgan | October 9, 2024 Tor Browser 13.5.7 is now available from the Tor Browser download page and also from our distribution directory. This version includes important security updates to Firefox: https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/#CVE-2024-9680 Users should update immediately. Send us your feedback If you find a bug or have a suggestion for how we could improve this release, please let us know. Full changelog The full changelog since Tor Browser 13.5.6 i...

Tor Project Forum
Mozilla fixes Firefox zero-day actively exploited in attacks

Mozilla has issued an emergency security update for the Firefox browser to address a critical use-after-free vulnerability that is currently exploited in attacks.

BleepingComputer