With Safari Zero-Day Attacks, Russian SVR Hackers Targeted LinkedIn Users

This article has been indexed from E Hacking News – Latest Hacker News and IT Security News

 

Google security experts revealed details on four zero-day vulnerabilities that were undisclosed until they were exploited in the wild earlier this year. After discovering exploits leveraging zero-day vulnerabilities in Google Chrome, Internet Explorer, and WebKit, the engine used by Apple’s Safari web browser, Google Threat Analysis Group (TAG), and Google Project Zero researchers discovered the four security issues. 
CVE-2021-21166 and CVE-2021-30551 in Chrome, CVE-2021-33742 in Internet Explorer, and CVE-2021-1879 in WebKit were the four zero-day exploits found by Google researchers earlier this year while being abused in the wild. “We tie three to a commercial surveillance vendor arming govt backed attackers and one to likely Russian APT,” Google Threat Analysis Group’s Director Shane Huntley said. “Halfway into 2021, there have been 33 0-day exploits used in attacks that have been publicly disclosed this year — 11 more than the total number from 2020,” Google researchers added. “While there is an increase in the number of 0-day exploits being used, we believe greater detection and disclosure efforts are also contributing to the upward trend.” 
Despite the fact that the zero-day flaws for Chrome and Internet Explorer were developed and sold by the same vendor to customers all over the world looking to improve their surveillance capabilities, they were not employed in any high-profile operations. The CVE-2021-1879 WebKit/Safari bug, according to Google, was used “to target government officials from Western European countries by sending them malicious links,” via LinkedIn Messaging. 
The attackers were part of a likely Russian government-backed

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: With Safari Zero-Day Attacks, Russian SVR Hackers Targeted LinkedIn Users