Source |
The Hacker News |
Identifiant |
2359301 |
Date de publication |
2021-02-16 23:11:54 (vue: 2021-02-17 08:05:40) |
Titre |
Malvertisers Exploited WebKit 0-Day to Redirect Browser Users to Scam Sites (Recyclage) |
Texte |
A malvertising group known as "ScamClub" exploited a zero-day vulnerability in WebKit-based browsers to inject malicious payloads that redirected users to fraudulent websites gift card scams.
The attacks, first spotted by ad security firm Confiant in late June 2020, leveraged a bug (CVE-2021–1801) that allowed malicious parties to bypass the iframe sandboxing policy in the browser engine that |
Notes |
|
Envoyé |
Oui |
Condensat |
2020 2021–1801 allowed attacks based browser browsers bug bypass card confiant cve day engine exploited firm first fraudulent gift group iframe inject june known late leveraged malicious malvertisers malvertising parties payloads policy redirect redirected sandboxing scam scamclub scams security sites spotted users vulnerability webkit websites zero |
Tags |
Vulnerability
|
Stories |
|
Move |
|
Source |
Bleeping Computer |
Identifiant |
2355381 |
Date de publication |
2021-02-16 09:39:22 (vue: 2021-02-16 15:05:38) |
Titre |
Malvertisers exploited browser zero-day to redirect users to scams |
Texte |
The ScamClub malvertising group used a zero-day vulnerability in the WebKit web browser engine to push payloads that redirected to gift card scams. [...] |
Notes |
|
Envoyé |
Oui |
Condensat |
browser card day engine exploited gift group malvertisers malvertising payloads push redirect redirected scamclub scams used users vulnerability web webkit zero |
Tags |
Vulnerability
|
Stories |
|
Move |
|