Firefox zero-day was used in attack against Coinbase employees, not its users
Furthermore, the attacks used not one, but two Firefox zero-days, according to Philip Martin, a member of the Coinbase security team, which reported the attacks to Mozilla. “On Monday, Coinbase detected blocked an attempt by an attacker to leverage the reported 0-day, along with a separate 0-day Firefox sandbox escape, to target Coinbase employees,” Martin said. Several scenarios come to mind:
– the attackers discovered the same RCE bug on their own
– they obtained the info from an insider with access to Mozilla’s security bugs portal
– they compromised a Mozilla employee’s account and accessed the Bugzilla portal’s security section
– or, they hacked the Bugzilla portal, similar to an incident from 2015
Attackers targeted Coinbase and other cryptocurrency orgs
Fortunately, the two Firefox bugs, which were chained into one single exploit and deployed against Coinbase employees, was detected by Coinbase staffers.
Source: www.zdnet.com