Security News

Latest Firefox 95 Includes RLBox Sandboxing to Protect Browser from Malicious Code
2021-12-06 21:21

Mozilla is beginning to roll out Firefox 95 with a new sandboxing technology called RLBox that prevents untrusted code and other security vulnerabilities from causing "Accidental defects as well as supply-chain attacks." All major browsers are designed to run web content in their own sandboxed environment as a means to counter malicious sites from exploiting a browser vulnerability to compromise the underlying operating system.

Github cookie leakage – thousands of Firefox cookie files uploaded by mistake
2021-11-18 22:20

Two years ago, we wrote about the fact that incautious software developers had uploaded hundreds of thousands of private access control keys, entirely unintentionally, along with source code files that they did intend to make public. Blindly packaging all these files into an archive for uploading to your favourite public repository seems pretty harmless, given that all the files in the lua account are supposed to be public.

Thousands of Firefox users accidentally commit login cookies on GitHub
2021-11-18 20:04

Thousands of Firefox cookie databases containing sensitive data are available on request from GitHub repositories, data potentially usable for hijacking authenticated sessions. Aidan Martin, a security engineer at London-based rail travel service Trainline, alerted The Register to the public availability of these files after reporting his findings through HackerOne and being told by a GitHub representative that "Credentials exposed by our users are not in scope for our Bug Bounty program."

Mozilla sprinkles Firefox Relay with Premium fairy dust
2021-11-16 16:22

Mozilla hopes to ramp up the monetisation machine with a paid premium version of its Firefox Relay service, upping the current limit of five email aliases to a near-unlimited number. Firefox Relay hides a user's real email address behind an alias to both protect the user's identity and spare their inbox from spam.

Mozilla Firefox, the first Chromium alternative in the Windows Store
2021-11-09 18:02

Firefox is now available for download through Microsoft's Windows Store for Windows 10 and Windows 11 users, the first major web browser to be added after Opera was added in late September. Until today, Mozilla couldn't bring its web browser onto the Microsoft Store because Redmond's store policies required that all browsers submitted for inclusion had to use the engine provided by Windows.

Mozilla Firefox Blocks Malicious Add-Ons Installed by 455K Users
2021-10-26 15:44

The Firefox team said that the misbehaving Firefox add-ons they found in June - named Bypass and Bypass XM - were misusing the API to intercept and redirect users from downloading updates, accessing updated blocklists and updating remotely configured content. Mozilla has blocked the malicious add-ons in order to keep them from being installed by yet more users.

Malicious Firefox Add-ons Block Browser From Downloading Security Updates
2021-10-26 00:41

Mozilla on Monday disclosed it blocked two malicious Firefox add-ons installed by 455,000 users that were found misusing the Proxy API to impede downloading updates to the browser. The two extensions in question, named Bypass and Bypass XM, "Interfered with Firefox in a way that prevented users who had installed them from downloading updates, accessing updated blocklists, and updating remotely configured content," Mozilla's Rachel Tublitz and Stuart Colville said.

Mozilla blocks malicious add-ons installed by 455K Firefox users
2021-10-25 20:08

Mozilla blocked malicious Firefox add-ons installed by roughly 455,000 users after discovering in early June that they were abusing the proxy API to block Firefox updates. "Starting with Firefox 91.1, Firefox now includes changes to fall back to direct connections when Firefox makes an important request via a proxy configuration that fails."

Firefox now shows ads as sponsored address bar suggestions
2021-10-07 14:15

Mozilla is now showing ads in the form of sponsored Firefox contextual suggestions when U.S. users type in the URL address bar. While blog posts [1, 2] presenting it under the "Firefox Suggest" name were published in September, it was first mentioned in a Firefox changelog with the release of Firefox 93 two days ago and presented as a "Faster way to navigate the web."

Firefox improves advertising tracker blocking in private browsing
2021-10-06 10:01

Mozilla says that Firefox users will be better protected from advertising trackers while browsing the Internet in Private Browsing mode and using Strict Tracking Protection. The SmartBlock mechanism, introduced by Mozilla with the release of Firefox 87 in March, ensures that the Tracking Protection feature and Strict Mode don't break websites when blocking tracking scripts.