An ad on a news site in Russia was serving a Firefox exploit that searched for sensitive files and uploaded them to a server that appears to be in Ukraine. This morning Mozilla released security updates that fix the vulnerability. The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. All Firefox users are urged to update to Firefox 39.0.3.1.3. The fix has also been shipped in Firefox ESR 38.1.”]
Source: https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/