Berlin – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 17 Jul 2025 22:14:43 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Berlin – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/ https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/#respond Thu, 17 Jul 2025 22:14:42 +0000 https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/

VMware

VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.

Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.

These flaws are described in the security advisory as:

  • CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. Nguyen Hoang Thach of STARLabs SG used this flaw at Pwn2Own.
  • CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. This flaw was used by Corentin BAYET of REverse Tactics at Pwn2Own.
  • CVE-2025-41238: VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. Thomas Bouzerar and Etienne Helluy-Lafont of Synacktiv at Pwn2Own used this flaw.

The fourth flaw, tracked as CVE-2025-41239, received a 7.1 rating as it is an information disclosure. It was also discovered by Corentin BAYET of REverse Tactics, who chained with CVE-2025-41237 during the hacking contest.

VMware has not provided any workarounds, and the only way to fix these vulnerabilities is to install the new versions of the software.

It should be noted that CVE-2025-41239 impacts VMware Tools for Windows, which requires a different upgrade process.

These vulnerabilities were demonstrated as zero-days during the Pwn2Own Berlin 2025 hacking contest, where security researchers collected $1,078,750 after exploiting 29 zero-day vulnerabilities.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/feed/ 0 48217
Nominis Wins ‘Product Innovation Award’ at Mastercard Fintech Finals in Berlin https://earlybirdsinvest.com/nominis-wins-product-innovation-award-at-mastercard-fintech-finals-in-berlin/ https://earlybirdsinvest.com/nominis-wins-product-innovation-award-at-mastercard-fintech-finals-in-berlin/#respond Thu, 10 Jul 2025 19:28:37 +0000 https://earlybirdsinvest.com/nominis-wins-product-innovation-award-at-mastercard-fintech-finals-in-berlin/

[PRESS RELEASE – Tel Aviv, Israel, July 10th, 2025]

Nominis, the blockchain intelligence platform used by cryptocurrency startups and law enforcement, has won the Product Innovation Award at the Mastercard Fintech Competition in Berlin. This is Nominis’ second Mastercard award this year.

The judges recognized Nominis for building the first real-time KYT platform that combines on-chain data with off-chain intelligence from the Dark Web, Deep Web, open sources, and behavioral signals.

CEO Snir Levi accepted the award remotely and stated:

“Nominis was built for the realities of 2025, where off-chain risks surface first, in the Dark Web, social media, and beyond. Most KYT tools weren’t designed for that. This award validates our approach: complete transaction context, in real time, across over 70 blockchains.”

Nominis Vue, the core platform, monitors blockchain and crypto wallet, trading, and mining transactions in real time, detects suspicious wallet behavior, and flags money laundering and sanction evasion patterns. It includes case management, automated investigations, and real-time risk scoring.

As countries like Dubai and Singapore increase enforcement, real-time KYT is becoming a standard. Nominis supports both startups and regulators in navigating that shift.

The award highlights Nominis’ role in building safer crypto infrastructure, one transaction at a time.

For more information, users can visit nominis.io

About Nominis

NOMINIS is a crypto intelligence company. Nominis provides clients with a platform for KYT and Blockchain investigation. Through constant monitoring of the blockchain, and clear/deep/dark web scans and AI analysis, Nominis proactively detects potential threats before they escalate, including terror-financing and illegal money-laundering transactions.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/nominis-wins-product-innovation-award-at-mastercard-fintech-finals-in-berlin/feed/ 0 46899
Ethereum Berlin Upgrade Announcement https://earlybirdsinvest.com/ethereum-berlin-upgrade-announcement/ https://earlybirdsinvest.com/ethereum-berlin-upgrade-announcement/#respond Tue, 01 Jul 2025 13:45:27 +0000 https://earlybirdsinvest.com/ethereum-berlin-upgrade-announcement/

TL;DR

  • Berlin is ready to be deployed!
  • We’re moving fast: the first testnet to upgrade, Ropsten, is scheduled to upgrade on March 10th. Mainnet is scheduled for April 15th.
  • If you are running an Ethereum node, you should upgrade it to a Berlin-compatible version ASAP for testnets and before April 7th for mainnet.
  • See below for the list of Berlin-compatible client versions and details on the EIPs included in the upgrade.
  • The Besu client has reported a bug in their previous Berlin release. Besu users should upgrade to version 21.1.2.

Berlin Timing

After months and months of planning, Berlin is finally here! The upgrade, which follows the Istanbul and Muir Glacier upgrades, is scheduled to go live on the Ethereum mainnet at block 12 244 000. We expect this to happen around Wednesday, April 15, 2021, but because of block time variability, the exact date may change.

Prior to being deployed on mainnet, the upgrade will go live on the Ropsten, Goerli, and Rinkeby testnets. The entire release schedule is as follows:

Network Block Number Expected Date
Ropsten 9 812 189 10 Mar 2021
Goerli 4 460 644 17 Mar 2021
Rinkeby 8 290 928 24 Mar 2021
Mainnet 12 244 000 15 Apr 2021

Ethereum node operators should upgrade their nodes prior to the fork block on the networks they want to participate in. Due to block time variability, it is recommended to update several days before the expected date. See the section below for the appropriate client versions to upgrade to.

Client Versions

In order to be compatible with the Berlin upgrade, node operators will need to upgrade the client version that they run. The versions, listed below for each client, support Berlin across all Ethereum networks, both testnets and mainnet.


Note, the Besu team have reported a bug in their 21.1.1 release related to Berlin (link). Besu users should upgrade to the 21.1.2 release in order to remain compatible with Berlin. Additionally, TurboGeth will not have a client release ready for the first testnets, but will have a release prior to mainnet. We will update this post as their release becomes availabe. Trinity is now deprecated and will not be supporting the Berlin upgrade.

Berlin EIPs

The Berlin upgrade introduces the following EIPs to the Ethereum network:


To learn more about each EIP, see the Ethereum Cat Herder’s Berlin Overview post.

FAQ

Why “Berlin”?

After Istanbul, we ran out of names for our planned network upgrades. It was suggested to use Devcon city names for upgrades, and we stuck with it! Berlin is where Devcon 0 took place, and the next upgrade will be called London, where Devcon 1 happened.

As an Ethereum user or Ether holder, is there anything I need to do?

If you use an exchange (such as Coinbase, Kraken, or Binance), a web wallet service (such as Metamask, MyCrypto, or MyEtherWallet), a mobile wallet service (such as Coinbase Wallet, Status.im, or Trust Wallet), or a hardware wallet (such as Ledger, Trezor, or KeepKey) you do not need to do anything unless you are informed to take additional steps by your exchange or wallet service.

As a node operator or miner, what do I need to do?

Download the latest version of your Ethereum client, as listed in the table above.

What happens if I am a miner or node operator and I do not participate in the upgrade?

If you are using an Ethereum client that is not updated to the latest version (listed above), your client will sync to the pre-fork blockchain once the upgrade occurs. You will be stuck on an incompatible chain following the old rules and you will be unable to send Ether or operate on the post-upgrade Ethereum network.

What is a network upgrade in Ethereum-land?

A network upgrade is a change to the underlying Ethereum protocol, creating new rules to improve the system. The decentralized nature of blockchain systems makes a network upgrade more difficult. Network upgrades in a blockchain require cooperation and communication with the community, as well as with the developers of the various Ethereum clients in order for the transition to go smoothly.

What happens during a network upgrade?

After the community comes to an agreement concerning which changes should be included in the upgrade, changes to the protocol are written into the various Ethereum clients, such as geth, Open Ethereum, Besu and Nethermind. The protocol changes are activated at a specific block number. Any nodes that have not been upgraded to the new ruleset will be abandoned on the old chain where the previous rules continue to exist.

Thank You!

A big thanks to the Ethereum community and to all Ethereum developers across all clients and platforms who came together to provide input, thoughts, and contribution for Berlin 😁🇩🇪

Now, onto London 🇬🇧!

Disclaimer

This is an emergent and evolving highly technical space. If you choose to implement the recommendations in this post and continue to participate, you should make sure you understand how it impacts you. You should understand that there are risks involved including but not limited to risks like unexpected bugs. By choosing to implement these recommendations, you alone assume the risks of the consequences. This post and recommendations are not a sale of any kind, and do not create any warranties of any kind including but not limited to anything related to the Ethereum network, or the Ethereum clients referred to herein.

]]>
https://earlybirdsinvest.com/ethereum-berlin-upgrade-announcement/feed/ 0 45169