Hkcert Critical Vulnerabilities Discovered in Mozilla Products
Article Content
- •Severe vulnerabilities in Mozilla products could lead to arbitrary code execution.
- •Attackers may exploit these vulnerabilities to gain full user rights on affected systems.
- •No known exploitation has been reported, but users are urged to apply patches.
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and create new accounts with full user rights. Users with administrative privileges are at greater risk compared to those with limited rights. The vulnerabilities include a remote code execution vector and a denial of service condition. As of now, there are no reports of these vulnerabilities being exploited in the wild. Users are advised to apply the fixes issued by Mozilla to mitigate risks. The vulnerabilities are categorized under Initial Access tactics and Drive-by Compromise techniques. Specific CVEs have not been disclosed in the articles.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (44)
Following this threat?
Track Bad Rabbit, Andariel and Dark Caracal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Cisco Talos Launches CAIRN to Combat AI-Integrated Malware On September 22, 2026, Cisco Talos released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware. The first documented malware analyzed with CAIRN is CLOSEDQUORUM, a Windows implant that autonomously delegates command-and-control decisions to commercial large language models…