Source |
Bleeping Computer |
Identifiant |
2355381 |
Date de publication |
2021-02-16 09:39:22 (vue: 2021-02-16 15:05:38) |
Titre |
Malvertisers exploited browser zero-day to redirect users to scams |
Texte |
The ScamClub malvertising group used a zero-day vulnerability in the WebKit web browser engine to push payloads that redirected to gift card scams. [...] |
Notes |
|
Envoyé |
Oui |
Condensat |
browser card day engine exploited gift group malvertisers malvertising payloads push redirect redirected scamclub scams used users vulnerability web webkit zero |
Tags |
Vulnerability
|
Stories |
|
Move |
|
Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2021-02-16 23:11:54 |
(Déjà vu) Malvertisers Exploited WebKit 0-Day to Redirect Browser Users to Scam Sites (lien direct) |
A malvertising group known as "ScamClub" exploited a zero-day vulnerability in WebKit-based browsers to inject malicious payloads that redirected users to fraudulent websites gift card scams.
The attacks, first spotted by ad security firm Confiant in late June 2020, leveraged a bug (CVE-2021–1801) that allowed malicious parties to bypass the iframe sandboxing policy in the browser engine that |
Vulnerability
|
|
|