threat-intel Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials A campaign of malicious Firefox add-ons, dubbed the "Offside Wallet Theft Factory", has been quietly stealing cryptocurrency wallet seed phrases and browser credentials since March 2026. Researchers identified 40 out of 77 linked extensions as actively stealing data, with the remaining extensions masquerading as VPNs o… Graham Cluley · 6d ago High browsercryptomalware
threat-intel 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets A group of 40 malicious Firefox extensions, disguised as Web3 products like OKX and Rabby Wallet, are stealing user wallet secrets. These extensions, part of a larger campaign dubbed ‘Offside Wallet Theft Factory,’ have… The Hacker News · Aug 20, 2026 High firefoxwalletextension
vulnerability Chrome, Firefox Updates Patch Dozens of Vulnerabilities Google and Mozilla have released security updates for Chrome and Firefox, addressing a significant number of vulnerabilities, including critical and high-severity flaws. These updates aim to prevent exploitation of issue… SecurityWeek · Aug 19, 2026 High vulnerabilitypatchsecurity
threat-intel Multiples vulnérabilités dans les produits Mozilla (19 août 2026) Mozilla has disclosed multiple vulnerabilities across its Firefox and Thunderbird products. These vulnerabilities include potential for remote code execution, denial of service, and information disclosure. Affected versi… CERT-FR · Aug 19, 2026 High CVE-2026-74934CVE-2026-74935CVE-2026-74936vulnerabilityfirefoxthunderbird
threat-intel Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The i… The Register · Aug 11, 2026 High key-managementfirefoxvulnerability
supply-chain Mozilla Issues New Firefox GPG Key Following Exposure Mozilla has revoked a compromised GPG signing key used for Firefox and Thunderbird, following its accidental exposure in a GitHub repository. While the immediate risk was mitigated due to limited access, the incident hig… SecurityWeek · Aug 11, 2026 Medium gpgsupply-chainkey-rotation
vulnerability Vulnérabilité dans Mozilla Firefox pour Android (05 août 2026) Mozilla has announced a vulnerability in Firefox for Android that could allow an attacker to compromise user data confidentiality. Users running versions of Firefox for Android prior to 153.0.3 are at risk and should upd… CERT-FR · Aug 5, 2026 Medium CVE-2026-18809firefoxandroidvulnerability
vulnerability Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser Researchers at Nebula Security discovered a vulnerability in Firefox's JIT compiler that allows a single malicious webpage visit to compromise the browser, including Tor Browser. This vulnerability, CVE-2026-10702, can b… The Hacker News · Jul 29, 2026 High CVE-2026-10702CVE-2026-43499jitsifirefoxexploit
vulnerability Multiples vulnérabilités dans Mozilla Thunderbird (23 juillet 2026) Mozilla Thunderbird contains multiple vulnerabilities that could lead to data compromise, security policy bypass, denial of service, remote code execution, and privilege escalation. These vulnerabilities are present in v… CERT-FR · Jul 23, 2026 High CVE-2026-14899CVE-2026-15718CVE-2026-15719vulnerabilitysecurityfirefox
threat-intel Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026) Multiple vulnerabilities have been discovered in Mozilla products. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service. These vulnerabilities are… CERT-FR · Jul 22, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-16349vulnerabilityfirefoxsecurity
vulnerability Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Multiple security flaws have been patched across Firefox, Chrome, Adobe products (including ColdFusion, Commerce, Experience Manager, and Illustrator), and VMware. Mozilla addressed two critical vulnerabilities in Firefo… The Hacker News · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764UNsecurity updatevulnerabilitypatch
vulnerability Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Google and Mozilla have released security updates for Chrome and Firefox, addressing several critical vulnerabilities. These updates include patches for zero-day exploits and prevent potential attacks. While exploit code… SecurityWeek · Jul 15, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-15764vulnerabilityzero-daypatch
vulnerability Multiples vulnérabilités dans Mozilla Firefox (15 juillet 2026) Mozilla has announced multiple security vulnerabilities in Firefox, allowing attackers to bypass security policies and potentially cause unspecified security problems. These vulnerabilities require immediate patching to… CERT-FR · Jul 15, 2026 Medium CVE-2026-14906CVE-2026-15718CVE-2026-15719firefoxvulnerabilitysecurity