Google fixes another Chrome zero-day exploited in the wild

For the third time in a year, Google has fixed a Chrome zero-day (CVE-2020-6418) that is being actively exploited by attackers in the wild. About CVE-2020-6418 No details have been shared about the attacks and about the flaw itself, apart from the shor… Continue reading Google fixes another Chrome zero-day exploited in the wild

Mozilla Firefox, Microsoft Edge succumb in web browser competition at Pwn2Own

The first day of this year’s Pwn2Own competition featured successful zero-day exploits on a popular web browser, and day two was no different, with the “Fluoroacetate” duo of Amat Cama and Richard Zhu turning their attention to Mozilla’s Firefox and Microsoft’s Edge. The team took home another $180,000 for their attacks, bringing their overall winnings to $340,000 for the competition, which highlights critical bugs in widely distributed software. Thursday’s winners also included Niklas Baumstark, who won $40,000 for a Firefox attack, and Arthur Gerkis of Exodus Intelligence, who won $50,000 for successfully targeting Edge. Competitors spend months preparing for the annual Pwn2Own hacking contest in Vancouver, which takes place during the CanSecWest security conference. Participants are tasked with trying to find vulnerabilities in widely used technology, and rewarded with cash prizes. They are only given a short amount of time to demonstrate their exploits for the crowd and judges. Team Flouroacetate’s attacks on […]

The post Mozilla Firefox, Microsoft Edge succumb in web browser competition at Pwn2Own appeared first on CyberScoop.

Continue reading Mozilla Firefox, Microsoft Edge succumb in web browser competition at Pwn2Own

CEO of Company Behind Tor Browser Exploit: “I Wanted to Help Take a Person Down”

Logan Brown, the president and CEO of Exodus Intelligence, described some of the dynamics between law enforcement and the exploit industry during a recent panel. Continue reading CEO of Company Behind Tor Browser Exploit: “I Wanted to Help Take a Person Down”

Putting Apple Bug Bounty Rewards in Perspective

Competing zero-day acquisition programs pay out much more than Apple’s new bug bounty program, but researchers used to submitting bugs gratis to Apple aren’t complaining much. Continue reading Putting Apple Bug Bounty Rewards in Perspective