bug – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 09 Sep 2025 14:08:05 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 bug – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Anti-spam bug blocks links in Exchange Online, Teams https://earlybirdsinvest.com/anti-spam-bug-blocks-links-in-exchange-online-teams/ https://earlybirdsinvest.com/anti-spam-bug-blocks-links-in-exchange-online-teams/#respond Tue, 09 Sep 2025 14:08:05 +0000 https://earlybirdsinvest.com/anti-spam-bug-blocks-links-in-exchange-online-teams/

Spam

​Microsoft is working to resolve a known issue that causes an anti-spam service to mistakenly block Exchange Online and Microsoft Teams users from opening URLs and quarantine some of their emails.

In a service alert seen by BleepingComputer, the company stated that the issue is caused by the anti-spam engine incorrectly tagging URLs contained within other URLs as potentially malicious, which has also led to some emails being quarantined.

The issues began impacting Exchange Online and Microsoft Teams users on September 5th, when Redmond said that admins might see alerts titled “A potentially malicious URL click was detected involving one user,” even though the URLs had already been confirmed as safe.

“We’ve identified over 6,000 URLs that are affected and are working to unblock them before replaying messages to recover any messages or URLs that were incorrectly flagged,” Microsoft said the day it discovered the bug.

“Redmond’s engineers have deployed a fix that addresses these problems by ensuring that the syncs no longer enter the quarantine state, after a previous configuration change that would’ve changed the configured delay interval to one hour wasn’t successful.”

While Microsoft engineers have partially resolved these false positive issues, they are still working to address the impact caused by more URLs being disabled by its faulty anti-spam models.

“We’ve identified a new subset of URLs that are impacted and we’re working to address the new set and any residual impacted messages. We are confident that a majority of the impact has been resolved, and we’re actively addressing lingering impact while we perform our root cause analysis,” the company added in a September 8th update.

Although the company has yet to disclose the number of customers or the regions affected by these ongoing anti-spam problems, this service issue has been classified as an incident, which usually involves noticeable user impact.

Microsoft has addressed similar issues since the start of the year, resulting in emails being incorrectly tagged as spam or quarantined. For instance, in May, Microsoft resolved another issue causing a machine learning model to incorrectly flag emails from Gmail accounts as spam in Exchange Online.

Redmond fixed another machine-learning bug that mistakenly flagged Adobe emails in Exchange Online as spam one month earlier, as well as an Exchange Online false positive that caused anti-spam systems to incorrectly quarantine some users’ emails in March.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/anti-spam-bug-blocks-links-in-exchange-online-teams/feed/ 0 57564
This bounty hunter reported a critical bug to Apple. He only got $1,000 https://earlybirdsinvest.com/this-bounty-hunter-reported-a-critical-bug-to-apple-he-only-got-1000/ https://earlybirdsinvest.com/this-bounty-hunter-reported-a-critical-bug-to-apple-he-only-got-1000/#respond Thu, 31 Jul 2025 02:45:25 +0000 https://earlybirdsinvest.com/this-bounty-hunter-reported-a-critical-bug-to-apple-he-only-got-1000/

]]>
https://earlybirdsinvest.com/this-bounty-hunter-reported-a-critical-bug-to-apple-he-only-got-1000/feed/ 0 50600
lnd v0.19.2 Released with key bug fixes and performance upgrades https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/ https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/#respond Wed, 16 Jul 2025 22:41:16 +0000 https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/

Today, a new version of Lightning Network Daemon (LND), version 0.19.2, has been released. This update focuses primarily on bug fixes and performance improvements.

Key fixes include bugs that missed payment confirmation, rare issues that could freeze nodes during startup, and memory leaks that cause the software to use more resources over time. It also fixes crashes that can occur when a node is up in a specific mode or backup process.

This release includes an option migration to reduce the size of the “Attension Log Database” (sphinxReplay.db) to reduce disk and memory usage. This cleanup will run automatically unless it is turned off in the settings.

“Migration is optional, but by default it is turned on,” the release notes said. “If you run into problems, you can opt out of the migration by setting NO-GC-Decayed-Log = True in Config. This migration does not prevent you from being downgraded to the previous v0.19.x-beta version.”

Code Health.

Other changes include better handling of peer-to-peer (P2P) connections, better tracking log payments, and more accurate pricing calculations. This update also improves compatibility with test networks and adds small updates to the Command Line Tool (LNCLI).

Check the Docker image.

Additional improvements include improved connection handling, improved AUX traffic, and updates to the RPC interface, making debugging easier. Lightning Seed Service supports TestNet4 and Signet, making it easier to peer discovery of new nodes.

Added RPC.

This update was built using go1.23.9, allowing others to check that the released files match the original source code. Docker users can also run scripts to confirm the installation before starting the container.

Check the FAG itself.

This release can be verified using PGP signatures and opertised stamps to ensure that it has not been tampered with. Details and instructions are available here.

]]>
https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/feed/ 0 48025
DanaBot malware operators exposed via C2 bug added in 2022 https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/ https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/#respond Wed, 11 Jun 2025 06:50:54 +0000 https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/

Spying

A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action.

DanaBot is a malware-as-a-service (MaaS) platform active from 2018 through 2025, used for banking fraud, credential theft, remote access, and distributed denial of service (DDoS) attacks.

Zscaler’s ThreatLabz researchers who discovered the vulnerability, dubbed ‘DanaBleed,’ explain that a memory leak allowed them to gain a deep peak into the malware’s internal operations and the people behind it.

Leveraging the flaw to collect valuable intelligence on the cybercriminals enabled an international law enforcement action named ‘Operation Endgame’ to take DanaBot infrastructure offline and indict 16 members of the threat group.

DanaBleed

The DanaBleed flaw was introduced in June 2022 with DataBot version 2380, which added a new command and control (C2) protocol.

A weakness in the new protocol’s logic was in the mechanism that generated the C2 server’s responses to clients, which was supposed to include randomly generated padding bytes but didn’t initialize newly allocated memory for these.

Zscaler researchers collected and analyzed a large number of C2 responses that, due to the memory leak bug, contained leftover data fragments from the server’s memory.

This exposure is analogous to the HeartBleed problem discovered in 2014, impacting the ubiquitous OpenSSL software.

As a result of DanaBleed, a broad array of private data was exposed to the researchers over time, including:

  • Threat actor details (usernames, IP addresses)
  • Backend infrastructure (C2 server IPs/domains)
  • Victim data (IP addresses, credentials, exfiltrated info)
  • Malware changelogs
  • Private cryptographic keys
  • SQL queries and debug logs
  • HTML and web interface snippets from the C2 dashboard

For over three years, DanaBot operated in a compromised mode without its developers or clients ever realizing they were being exposed to security researchers.

This allowed targeted law enforcement action when enough data had been collected.

Leaked HTML data on the C2 server responses
Leaked HTML data on the C2 server responses
Source: Zscaler

Although DanaBot’s core team in Russia was merely indicted and not arrested, the seizure of critical C2 servers, 650 domains, and nearly $4,000,000 in cryptocurrency has effectively neutralized the threat for now.

It is not unlikely that the threat actors attempt to return to cybercrime operations in the future, but reduced trust from the hackers’ community will be a significant obstacle for them.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/feed/ 0 41367
Google patches new Chrome zero-day bug exploited in attacks https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/ https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/#respond Tue, 03 Jun 2025 11:09:32 +0000 https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/

Google Chrome

Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year.

“Google is aware that an exploit for CVE-2025-5419 exists in the wild,” the company warned in a security advisory published on Monday.

This high-severity vulnerability is caused by an out-of-bounds read and write weakness in Chrome’s V8 JavaScript engine, reported one week ago by Clement Lecigne and Benoît Sevens of Google’s Threat Analysis Group.

Google says the issue was mitigated one day later by a configuration change the company pushed to the Stable channel across all Chrome platforms.

On Monday, it also fixed the zero-day with the release of 137.0.7151.68/.69 for Windows/Mac and 137.0.7151.68 for Linux, versions that are rolling out to users in the Stable Desktop channel over the coming weeks.

While Chrome will automatically update when new security patches are available, users can speed up the process by going to the Chrome menu > Help > About Google Chrome, letting the update finish, and clicking the ‘Relaunch’ button to install it immediately.

Chrome 137.0.7151.69

​While Google has already confirmed that CVE-2025-5419 is being exploited in the wild, the company will not share additional information regarding these attacks until more users have patched their browsers.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

This is Google’s third Chrome zero-day vulnerability since the start of the year, with two more patched in March and May.

The first, a high-severity sandbox escape flaw (CVE-2025-2783) discovered by Kaspersky’s Boris Larin and Igor Kuznetsov, was used to deploy malware in espionage attacks targeting Russian government organizations and media outlets.

The company released another set of emergency security updates in May to patch a Chrome zero-day that could let attackers take over accounts following successful exploitation.

Last year, Google patched 10 zero-days that were either demoed during the Pwn2Own hacking competition or exploited in attacks.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/feed/ 0 39879
Secured #4: Bug Bounty Rewards now up to $250,000 USD https://earlybirdsinvest.com/secured-4-bug-bounty-rewards-now-up-to-250000-usd/ https://earlybirdsinvest.com/secured-4-bug-bounty-rewards-now-up-to-250000-usd/#respond Wed, 14 May 2025 16:39:32 +0000 https://earlybirdsinvest.com/secured-4-bug-bounty-rewards-now-up-to-250000-usd/

The Ethereum Foundation Bug Bounty Program is one of the earliest and longest running programs of its kind. It was launched in 2015 and targeted the Ethereum PoW mainnet and related software. In 2020, a second Bug Bounty Program for the new Proof-of-Stake Consensus Layer was launched, running alongside the original Bug Bounty Program.

The split of these programs is historic due to the way the Proof-of-Stake Consensus Layer was architected separately and in parallel to the existing Execution Layer (inside the PoW chain). Since the launch of the Beacon Chain in December of 2020, the technical architecture between the Execution Layer and the Consensus Layer has been distinct, except for the deposit contract, so the two bug bounty programs have remained separated.

In light of the coming Merge, today we are happy to announce that these two programs have been successfully merged by the awesome ethereum.org team, and that the max bounty reward has been substantially increased!

Merge (of the Bug Bounty Programs) ✨

With The Merge approaching, the two previously disparate bug bounty programs have been merged into one.

As the Execution Layer and Consensus Layer become more and more interconnected, it is increasingly valuable to combine the security efforts of these layers. There are already multiple efforts being organized by client teams and the community to further increase knowledge and expertise across the two layers. Unifying the Bounty Program will further increase visibility and coordination efforts on identifying and mitigating vulnerabilities.

Increased Rewards 💰

The max reward of the Bounty Program is now 250,000(paidoutinETHorDAI)forvulnerabilitiesinscope.UpgradesliveonpublictestnetsandtargetedforaMainnetreleasearealsoscope,andrewardsaredoubledduringthistime,whichmeansthatthemaxrewardis250,000 (paid out in ETH or DAI) for vulnerabilities in scope. Upgrades live on public testnets and targeted for a Mainnet release are also scope, and rewards are doubled during this time, which means that the max reward is 500,000 during these periods!

In total, this marks a 10x increase from the previous maximum payout on Consensus Layer bounties and a 20x increase from the previous max payout on Execution Layer bounties.

Impact Measurement 💥

The Bug Bounty Program is primarily focused on securing the base layer of the Ethereum Network. With this in mind, the impact of a vulnerability is in direct correlation to the impact on the network as a whole.

While, for example, a Denial of Service vulnerability found in a client being used by <1% of the network would certainly cause issues for the users of this client, it would have a higher impact on the Ethereum Network if the same vulnerability existed in a client used by >30% of the network.

Visibility 👀

In addition to the merge of the bounty programs and increase of the max reward, multiple steps have been taken to clarify how to report vulnerabilities.

Github Security

Repositories such as ethereum/consensus-specs and ethereum/go-ethereum now contain information on how to report vulnerabilities in SECURITY.md files.

security.txt

security.txt is implemented and contains information about how to report vulnerabilities. The file itself can be found here.

DNS Security TXT

DNS Security TXT is implemented and contains information about how to report vulnerabilities. This entry can be viewed by running dig _security.ethereum.org TXT.

How can you get started? 🔨

With nine different clients written in various languages, Solidity, the Specifications, and the deposit smart contract all within the scope of the bounty program, there is a plenty for bounty hunters to dig into.

If you’re looking for some ideas of where to start your bug hunting journey, take a look at the previously reported vulnerabilities. This was last updated in March and contains all the reported vulnerabilities we have on record, up until the Altair network upgrade.

We’re looking forward to your reports! 🐛

]]>
https://earlybirdsinvest.com/secured-4-bug-bounty-rewards-now-up-to-250000-usd/feed/ 0 36209
iOS 18.4.1 fixes two serious security vulnerabilities and wireless CarPlay bug https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/ https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/#respond Thu, 17 Apr 2025 06:20:22 +0000 https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/

]]>
https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/feed/ 0 31243
Crypto Goes Continental: 33% Of French Catch The Bug, Italians Go Full Bull https://earlybirdsinvest.com/crypto-goes-continental-33-of-french-catch-the-bug-italians-go-full-bull/ https://earlybirdsinvest.com/crypto-goes-continental-33-of-french-catch-the-bug-italians-go-full-bull/#respond Sun, 13 Apr 2025 14:24:24 +0000 https://earlybirdsinvest.com/crypto-goes-continental-33-of-french-catch-the-bug-italians-go-full-bull/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

France experiences a sudden surge in cryptocurrency interest as one-third of its population now intend to purchase digital coins in 2025. This represents a huge increase in potential adoption even after recent market slowdowns. The trend indicates an increasing mainstream acceptance of cryptocurrencies throughout Europe with different rates of adoption in different countries.

French Crypto Appetite Grows To New Heights

In a recent study entitled “Web3 and Crypto in France and Europe,” 33% of French users intend to buy crypto assets by 2025. The research, carried out by the Association for the Development of Digital Assets (Adan), indicates that there is a 10-percentage point uptick in interest in coin investments among the French compared to what was previously indicated.

The annual report collected views from 2,000 residents of France as well as some 1,000 respondents across five other countries in Europe.

Source: Association for the Development of Digital Assets

Only 10% of French individuals own crypto assets while the interest in these assets grows consistently. This positions France behind several other European nations, such as the United Kingdom (19%), the Netherlands (17%), and Belgium (17%), in real world adoption rates.

However, as enthusiastic as they are, the French are not the most enthusiastic digital currency users in Europe. That laurel falls to the Italians with 37% of the population stating interest in acquiring Bitcoin in 2012.

Banking And Financial Platforms Drive New Adoption

The crypto sector’s growing legitimacy plays a key role in attracting new investors. Based on the research findings, mainstream financial platforms like Revolut have become major gateways to cryptocurrency ownership. The neobank now serves as the second-largest acquisition platform, used by 24% of crypto users.

Total crypto market cap currently at $2.65 trillion. Chart: TradingView

Laurent Ovion, the president of Adan, explained that “companies in the sector are demonstrating sound ambitions and high resilience, despite ongoing challenges related to financing and access to banking services.” This indicates that the sector is still expanding despite challenges experienced in the traditional financial markets.

The French economic newspaper Les Echos outlined the results as follows: “Although the percentage of French people who own cryptocurrencies is falling slightly, almost one third of French people would be willing to purchase Bitcoin. Cryptocurrencies have never been so popular with the French.”

Image: Gem Wallet

Beyond Investment: New Use Cases Emerge

The report informs that the adoption of cryptocurrencies goes beyond basic investment purposes. The research determined that 48% of respondents have positive sentiments towards crypto in decentralized digital identity systems. Further, 24% support cryptocurrencies as a payment method, and 22% find opportunities in decentralized finance (DeFi).

European Adoption Indicates Progress Varied

The in-depth research, which is in its fourth edition, was conducted in collaboration with Deloitte professional services network and multinational market research company Ipsos. The research tries to monitor the evolution of crypto asset adoption by the wider population and examine the dynamics of the Web3 sector.

Featured image from Alexander Spatari via Getty Images, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/crypto-goes-continental-33-of-french-catch-the-bug-italians-go-full-bull/feed/ 0 30576
Bitcoin’s slowness is a feature, not a bug https://earlybirdsinvest.com/bitcoins-slowness-is-a-feature-not-a-bug/ https://earlybirdsinvest.com/bitcoins-slowness-is-a-feature-not-a-bug/#respond Mon, 24 Mar 2025 01:02:20 +0000 https://earlybirdsinvest.com/bitcoins-slowness-is-a-feature-not-a-bug/

The following is a guest post from Brendon Sedo, Initial Contributor at Core DAO.

Satoshi didn’t invent Bitcoin to be a generalist network — a jack of all trades, master of none. Bitcoin deliberately trades speed and scalability for decentralization and security. But contrary to popular myths, this isn’t an obstacle to building new Bitcoin-based applications. 

Slowness is Bitcoin’s strength, not its weakness. And the ‘Building on Bitcoin’ movement will succeed only if devs embrace, inherit Bitcoin’s slow architecture while strategically working ‘around the edges.’ 

Don’t Try to Change Bitcoin

Bitcoin’s slowness is crucial to its security model and transaction confirmation mechanism.

Instead of relying on centralized intermediaries, Bitcoin achieves trustless transaction finality through Proof-of-Work (PoW) consensus, prioritizing security over speed. The resource-intensive and time-consuming PoW provides a computational guarantee to prevent malicious actors from altering Bitcoin’s transaction history. 

The 10-minute block confirmation time is thus one of Bitcoin’s core security features, albeit among the most fundamental ones.  

A shorter block time would increase the chances of orphaned blocks and forks. Whereas slower blocks ensure transactions are propagated across miners to confirm and agree on the longest chain. This negates the chances of validating wrong transactions and hard forks.

Yet Bitcoin’s scalability has always been a point of contention. So, devs have tried improving Bitcoin’s throughput and making it cheaper during high network congestion.

One such proposal was increasing the block size to reduce transaction fees while allowing for more data storage within a block. The community fought back, with good reason, and it led to the so-called Blocksize War

While larger Bitcoin blocks could have processed more transactions per second (TPS), making the chain faster and more scalable. It severely affects decentralization and network security. 

Larger blocks require more compute, so  it’s more expensive to run full nodes. This in turn means fewer miners securing the network, increasing centralization and consolidation risks in the hands of a wealthy elite. That’s precisely what Bitcoin was built to solve. 

The lesson: you don’t change Bitcoin; Bitcoin changes you. 

Higher TPS isn’t the right way to scale Bitcoin. In fact, Bitcoin’s core doesn’t need to scale at all. Past attempts have failed, and future attempts should too. 

Does that mean Bitcoin is just waiting there to become obsolete as a foundational network for crypto innovations? Not at all. 

Devs must stop trying to build directly on Bitcoin. Rather, they should leverage the network’s slowness-induced security and resilience and take a layered approach to building on Bitcoin. 

Bitcoin was, is, and will be the slow, secure core to the otherwise fleeting and risky world of crypto. 

Harness Slowness, Build ‘Around the Edges’

Bitcoin wasn’t designed for high programmability, complex smart contracts, high-throughput applications, and other such flashy concepts. 

It’s purpose is to provide a trust-minimized, censorship-resistant, and immutable foundation for sound money and secure financial transactions. Still Bitcoin can support programmable applications very well.  

The ‘Building on Bitcoin’ movement shows it’s possible to expand Bitcoin’s capabilities while preserving its security and decentralization.

Upgrades like Taproot have refined Bitcoin’s functionality, and enhancements like covenants and bridges will continue to do so in the future. 

However, the most transformative developments will happen beyond the base layer.

Bitcoin-powered innovations will happen at the edges, with scaling solutions like Layer-2s, Sidechains, Statechains, Rollups, and a range of interoperability protocols.

By building ‘around the edges,’ Bitcoin devs can achieve cutting-edge innovations and grow the ecosystem without compromising its core principles. These solutions will unlock entirely new use cases for the network and the asset class. 

This will simultaneously make Bitcoin more usable as a medium of exchange and collateral asset while maintaining Bitcoin’s integrity as the most secure financial network.

While other chains add features to compete for market share, Bitcoin has undergone rigorous scrutiny for any upgrade. The community has withheld hasty decisions to make the network faster so as not to compromise its unparalleled security.

Bitcoin’s slowness is the reason this network will endure. It forces devs to think of long-term solutions that reinforce rather than weaken the foundation. 

Devs mustn’t be psyops into chasing fleeting trends or making reckless compromises. Why should they when they have such a solid, secure, and resilient foundation to build on? 

Just like you don’t dig up a building’s basement to build a third floor above, you can build great things on Bitcoin without changing or hampering its core. That’s the way towards truly decentralized financial systems. 

Durable is what lasts. Bitcoin is durable, and apps built on this ecosystem can be, too. It’s not a question of if but whether developers are ready to adopt the right approach. Those who do will dominate the next decade of Bitcoin innovations. It has begun. 

Mentioned in this article
XRP Turbo
]]>
https://earlybirdsinvest.com/bitcoins-slowness-is-a-feature-not-a-bug/feed/ 0 26845
Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks https://earlybirdsinvest.com/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/ https://earlybirdsinvest.com/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/#respond Sun, 02 Mar 2025 16:28:24 +0000 https://earlybirdsinvest.com/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/

Hacker

Microsoft had discovered five Paragon Partition Manager BioNTdrv.sys driver flaws, with one used by ransomware gangs in zero-day attacks to gain SYSTEM privileges in Windows.

The vulnerable drivers were exploited in ‘Bring Your Own Vulnerable Driver’ (BYOVD) attacks where threat actors drop the kernel driver on a targeted system to elevate privileges.

“An attacker with local access to a device can exploit these vulnerabilities to escalate privileges or cause a denial-of-service (DoS) scenario on the victim’s machine,” explains a warning from CERT/CC.

“Additionally, as the attack involves a Microsoft-signed Driver, an attacker can leverage a Bring Your Own Vulnerable Driver (BYOVD) technique to exploit systems even if Paragon Partition Manager is not installed. “

As BioNTdrv.sys is a kernel-level driver, threat actors can exploit vulnerabilities to execute commands with the same privileges as the driver, bypassing protections and security software.

Microsoft researchers discovered all five flaws, noting that one of them, CVE-2025-0289, is leveraged in attacks by ransomware groups. However, the researchers did not disclose what ransomware gangs were exploiting the flaw as a zero-day.

“Microsoft has observed threat actors (TAs) exploiting this weakness in BYOVD ransomware attacks, specifically using CVE-2025-0289 to achieve privilege escalation to SYSTEM level, then execute further malicious code,” reads the CERT/CC bulletin.

“These vulnerabilities have been patched by both Paragon Software, and vulnerable BioNTdrv.sys versions blocked by Microsoft’s Vulnerable Driver Blocklist.”

The Paragon Partition Manager flaws discovered by Microsoft are:

  • CVE-2025-0288 – Arbitrary kernel memory write caused by the improper handling of the ‘memmove’ function, allowing attackers to write to kernel memory and escalate privileges.
  • CVE-2025-0287 – Null pointer dereference arising from a missing validation of a ‘MasterLrp’ structure in the input buffer, enabling the execution of arbitrary kernel code.
  • CVE-2025-0286 – Arbitrary kernel memory write caused by the improper validation of user-supplied data lengths, allowing attackers to execute arbitrary code.
  • CVE-2025-0285 – Arbitrary kernel memory mapping caused by the failure to validate user-supplied data, enabling privilege escalation by manipulating kernel memory mappings.
  • CVE-2025-0289 – Insecure kernel resource access caused by the failure to validate the ‘MappedSystemVa’ pointer before passing it to ‘HalReturnToFirmware,’ leading to potential compromise of system resources.

The first four vulnerabilities impact Paragon Partition Manager versions 7.9.1 and previous, while CVE-2025-0298, the actively exploited flaw, impacts version 17 and older.

Users of the software are recommended to upgrade to the latest version, which contains BioNTdrv.sys version 2.0.0, which addresses all of the mentioned flaws.

However, it’s important to note that even users who don’t have Paragon Partition Manager installed are not safe from attacks. BYOVD tactics don’t rely on the software being present on the target’s machine.

Instead, threat actors include the vulnerable driver with their own tools, allowing them to load it into Windows and escalate privileges.

Microsoft has updated its ‘Vulnerable Driver Blocklist’ to block the driver from loading in Windows, so users and organizations should verify the protection system is active.

You can check if the blocklist is enabled by going to Settings Privacy & securityWindows SecurityDevice securityCore isolationMicrosoft Vulnerable Driver Blocklist and making sure the setting is enabled.

Windows setting
Windows setting for vulnerable drivers blocklist
Source: BleepingComputer

A warning on Paragon Software’s site also warns that users must upgrade Paragon Hard Disk Manager by today, as it utilizes the same driver, which will be blocked by Microsoft today.

While it is unclear what ransomware gangs are exploiting the Paragon flaw, BYOVD attacks have become increasingly popular among cybercriminals as they allow them to easily gain SYSTEM privileges on Windows devices.

Threat actors known to be utilizing BYOVD attacks include Scattered Spider, Lazarus, BlackByte ransomware, LockBit ransomware, and many more.

For this reason, it is important to enable the Microsoft Vulnerable Driver Blocklist feature to prevent vulnerable drivers from being used on your Windows devices.

]]>
https://earlybirdsinvest.com/ransomware-gangs-exploit-paragon-partition-manager-bug-in-byovd-attacks/feed/ 0 22860