November 19, 2020 at 02:19PM

■■■■■ Remotely stealing cookies from Firefox for Android by visiting an exploit website (CVE-2020-15647). PoC: https://gist.github.com/kanytu/7fe0640c87b0f3e57bda51e784a7255d Research: https://medium.com/bugbountywriteup/firefox-and-how-a-website-could-steal-all-of-your-cookies-581fe4648e8d https://t.me/cKure/6056

November 18, 2020 at 03:06PM

■■■■□ Japan-Linked Organizations Targeted in Long-Running and Sophisticated Attack Campaign. https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-japan-espionage https://t.me/cKure/6048

November 18, 2020 at 11:35AM

■■■□□ Unknown threat actors are scanning for WordPress websites with Epsilon Framework themes installed on over 150,000 sites and vulnerable to Function Injection attacks that could lead to full site takeovers. These attacks use POST requests to admin-ajax.php and as such do not leave distinct log entries, though they will be visible Wordfence Live Traffic. https://www.bleepingcomputer.com/news/security/hackers-are-actively-probing-millions-of-wordpress-sites/…