Russian hackers exploit zero-day vulnerabilities in Firefox and Windows for targeted attacks

infosecurity-magazine.com

Russian hackers known as RomCom have exploited serious vulnerabilities in Mozilla Firefox and Windows to conduct targeted attacks. These zero-day flaws were discovered by ESET in October 2024 and have since been patched. The Firefox vulnerability, CVE-2024-9680, allowed attackers to execute code without user interaction. A second Windows vulnerability, CVE-2024-49039, enabled privilege escalation, further enhancing the attack's effectiveness. RomCom's method involved a fake website that redirected victims to the exploit. If successful, the attack installed a backdoor on the victim's computer, allowing the hackers to execute commands and download additional malicious software.


With a significance score of 4.3, this news ranks in the top 8% of today's 27482 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 9000 minimalists.