ScamClub Malvertising Leveraged Zero-Day Vulnerability in Browsers

Read the original article: ScamClub Malvertising Leveraged Zero-Day Vulnerability in Browsers


Originally reported by BleepingComputer, the malvertising group ScamClub leveraged a zero-day vulnerability in the WebKit browser engine in order to distribute payloads that redirected to gift card scams through malicious iframes. WebKit is used by Chrome and Safari browsers, and has received a patch to remove this vulnerability as of December 2, 2020. The vulnerability […]

The post ScamClub Malvertising Leveraged Zero-Day Vulnerability in Browsers appeared first on Binary Defense.


Read the original article: ScamClub Malvertising Leveraged Zero-Day Vulnerability in Browsers