Russian Hackers Exploit Firefox and Windows 0-Days to Deploy Backdoor
ID: e6a97e8e-6f35-579c-89f9-9ed2e61bcb9e
STIX ID: report--e6a97e8e-6f35-579c-89f9-9ed2e61bcb9e
Feed Name: HackRead
Threat Score
ESET revealed a RomCom (Russia-linked) campaign that chained two in-the-wild zero-days—a Firefox use-after-free (CVE-2024-9680, CVSS 9.8) and a Windows privilege-escalation bug (CVE-2024-49039, CVSS 8.8)—to escape the browser sandbox via malicious redirects and install a custom backdoor on targeted systems in government, pharmaceutical, legal and other sectors across Europe and North America; Mozilla and Microsoft released rapid patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
