Noticias
Scammers attack: Mozilla has a critical vulnerability, and Android applications steal data
Coinbase Security and Google security researcher Samuel Gross discovered a vulnerability in Mozilla Firefox browser that could manipulate Javascript objects. It has already been used to attack users of cryptocurrency. This is reported on Medium. The zero-day vulnerability received a CVE-2019-11707 identifier, and in Firefox, the bug was assigned a critical or highest threat level. "Critical vulnerability – it can be used […]


Coinbase Security and Google security researcher Samuel Gross discovered a vulnerability in Mozilla Firefox browser that could manipulate Javascript objects. It has already been used to attack users of cryptocurrency. This is reported on Medium .
The zero-day vulnerability received a CVE-2019-11707 identifier, and in Firefox, the bug was assigned a critical or highest threat level.
"Critical vulnerability – it can be used to launch an attacker's code and install software that does not require user interaction, except for normal viewing."
In fact, the attackers could force users to go to malicious sites and thus be able to execute arbitrary code on the devices of their victims. The scammers who used the bug could install programs, view, change or delete data, as well as create new accounts.
Users are urged to upgrade as soon as possible to the new version of Firefox 67.0.3 and Firefox ESR 60.7.1, in which the vulnerability is fixed.
Context: https://t.co/EQX4Ev42tx
– Samuel Groß (@ 5aelo) June 19, 2019
In addition, malicious applications for the Android OS were found. They could steal one-time two-factor authentication passwords using a notification system.
2FA & OTP codes.
It intercepts SMS notifications.
Discovered fake cryptocurrency exchanges with such functionality on the Play Store. https://t.co/t5Vtm3DrJW– Lukas Stefanko (@LukasStefanko) June 17, 2019
ESET researcher Lukash Stefanko has identified a number of applications (BTCTurk Pro Beta and BtcTurk Pro Beta), posing as the Turkish cryptocurrency exchange BtcTurk. They could steal account data and use it in services protected by two-factor authentication.
Note that at the beginning of the year, Google imposed restrictions on applications by banning them from accessing SMS messages and call logs without serious justification. However, the attackers were able to circumvent these limitations: applications request permission to check and manage notifications.
Once it was received, users were asked to enter their credentials from various cryptocurrency services in fake forms. The collected information was transferred to the attackers server, and they got access to notifications from other applications. It is noteworthy that fraudsters could also turn off the sound, notifying of incoming notifications, so that the victims did not even know about unauthorized intervention.
Thus, the researcher discovered filters that distinguish a kind of target applications, whose names contain the keywords gm, yandex, mail, k9, outlook, sms and messaging.
Recall, recently, analysts at ESET found a fake Trezor Mobile Wallet app in the Google Play store, disguised as a popular wallet and stealing users' cryptocurrency.
Subscribe to BlockchainJournal news on Facebook !
BlockchainJournal.news
BlockchainJournal.news
Compañías
ARK Invest Deshace Acciones de Coinbase y GBTC por Millones en Medio del Auge del Mercado

ARK Invest, liderada por Cathie Wood, continúa navegando sus movimientos estratégicos de acciones en el mercado, realizando ventas destacadas de acciones de Coinbase y Grayscale Bitcoin Trust (GBTC) en medio del continuo aumento de los precios del mercado.
Compañías
El Descuento de GBTC se Reduce a Medida que Aumenta el Precio de Bitcoin

Grayscale Bitcoin Trust (GBTC), uno de los vehículos de inversión en criptomonedas más grandes y populares, ha visto su descuento reducirse significativamente en los últimos días a medida que los alcistas continúan elevando su precio. Según datos de Kaiko, una plataforma de inteligencia blockchain, el descuento del GBTC, que mide la diferencia entre el precio de mercado y el valor liquidativo (NAV) del fideicomiso, está en su nivel más estrecho en años, con solo el 8% hasta ayer. (más…)
Compañías
IBM Presenta OSO, Diseñada Para el Almacenamiento en Frío de Activos Digitales

IBM presentó una nueva tecnología denominada «IBM Hyper Protect Offline Signing Orchestrator» (OSO), diseñada para gestionar activos digitales en almacenamiento en frío. Esta innovación surge como respuesta a los riesgos asociados con los procedimientos manuales y tiene como objetivo mantener los activos a una distancia segura de las conexiones a Internet. (más…)
-
Noticias7 años ago
Los principales eventos de la semana en la industria de bitcoin y blockboy (17 de septiembre de 2013 – 23 de septiembre de 2018)
-
Noticias6 años ago
24 países junto con el FMI discutieron futuras reglas y regulaciones para la regulación de la criptomoneda
-
Noticias7 años ago
Medios de comunicación: en Francia permitirá la compra de criptomoneda en tiendas de tabaco
-
Noticias7 años ago
Medios de comunicación: en vísperas de la OPI, los posibles inversores de la compañía minera Bitmain estaban mal informados
-
Noticias7 años ago
Descripción general del nuevo ASIC de Bitmain: ANTMINER S15 y T15: características y rentabilidad
-
Noticias6 años ago
¿Cómo almacenar una frase semilla mnemónica de una billetera de criptomonedas?
-
Noticias7 años ago
El índice de "índice de miedo y codicia" de Bitcoin alcanzó los valores mínimos
-
Noticias7 años ago
Aumento de la demanda de Ripple (XRP)