Hkcert Critical Vulnerabilities Discovered in Mozilla Products
Article Content
- •Severe vulnerabilities in Mozilla products could lead to arbitrary code execution.
- •Attackers may exploit these vulnerabilities to gain full user rights on affected systems.
- •No known exploitation has been reported, but users are urged to apply patches.
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and create new accounts with full user rights. Users with administrative privileges are at greater risk compared to those with limited rights. The vulnerabilities include a remote code execution vector and a denial of service condition. As of now, there are no reports of these vulnerabilities being exploited in the wild. Users are advised to apply the fixes issued by Mozilla to mitigate risks. The vulnerabilities are categorized under Initial Access tactics and Drive-by Compromise techniques. Specific CVEs have not been disclosed in the articles.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (44)
Following this threat?
Track Bad Rabbit, Andariel and Dark Caracal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korea's Lazarus Group Divided into Six Cyber Clusters Recent analysis by Sekoia and Kudelski Security reveals that North Korea's Lazarus Group operates through six distinct cyber clusters, focusing on espionage, financial activities, and sanctions evasion. The clusters include TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, each…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…