deploy – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 05 Sep 2025 13:31:37 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 deploy – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hackers exploited Sitecore zero-day flaw to deploy backdoors https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/ https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/#respond Fri, 05 Sep 2025 13:31:37 +0000 https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/

Hacker

Threat actors have been exploiting a zero-day vulnerability in legacy Sitecore deployments to deploy WeepSteel reconnaissance malware.

The flaw, tracked under CVE-2025-53690, is a ViewState deserialization vulnerability caused by the inclusion of a sample ASP.NET machine key in pre-2017 Sitecore guides.

Some customers reused this key in production, allowing attackers with knowledge of the key to craft valid, but malicious ‘_VIEWSTATE’ payloads that tricked the server into deserializing and executing them, leading to remote code execution (RCE).

The flaw isn’t a bug in ASP.NET itself, but a misconfiguration vulnerability created by reusing publicly documented keys that were never meant for production.

Exploitation activity

Mandiant researchers, who discovered the malicious activity in the wild, report that threat actors have been leveraging the flaw in multi-stage attacks.

The attackers target the ‘/sitecore/blocked. aspx’ endpoint, which contains an unauthenticated ViewState field, and achieve RCE under the IIS NETWORK SERVICE account by leveraging CVE-2025-53690.

The malicious payload they drop is WeepSteel, a reconnaissance backdoor that gathers system, process, disk, and network information, disguising its exfiltration as standard ViewState responses.

WeepSteel's information collection
WeepSteel’s information collection
Source: Mandiant

Mandiant observed the execution of reconnaissance commands on compromised environments, including whoami, hostname, tasklist, ipconfig /all, and netstat -ano.

In the next stage of the attack, the hackers deployed Earthworm (a network tunneling and reverse SOCKS proxy), Dwagent (a remote access tool), and 7-Zip, which is used to create archives of the stolen data.

Subsequently, they escalated their privileges by creating local administrator accounts (‘asp$,’ ‘sawadmin’), cached (SAM and SYSTEM hives) credentials dumping, and attempted token impersonating via GoTokenTheft.

Persistence was secured by disabling password expiration for these accounts, giving them RDP access, and registering Dwagent as a SYSTEM service.

The attack lifecycle
The attack lifecycle
Source: Mandiant

Mitigating CVE-2025-53690

CVE-2025-53690 impacts Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud, up to version 9.0, when deployed using the sample ASP.NET machine key included in pre-2017 documentation.

XM Cloud, Content Hub, CDP, Personalize, OrderCloud, Storefront, Send, Discover, Search, and Commerce Server are not impacted.

Sitecore published a security bulletin in coordination with Mandiant’s report, warning that multi-instance deployments with static machine keys are also at risk.

The recommended actions for potentially impacted administrators are to immediately replace all static values in web.config with new, unique keys, and ensure the element inside web.config is encrypted.

In general, it is recommended to adopt regular static machine key rotation as an ongoing security measure.

More information on how to protect ASP.NET machine keys from unauthorized access can be found here.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/feed/ 0 56895
Navan’s New AI Platform Lets Businesses Deploy Full Teams https://earlybirdsinvest.com/navans-new-ai-platform-lets-businesses-deploy-full-teams/ https://earlybirdsinvest.com/navans-new-ai-platform-lets-businesses-deploy-full-teams/#respond Mon, 30 Jun 2025 02:05:14 +0000 https://earlybirdsinvest.com/navans-new-ai-platform-lets-businesses-deploy-full-teams/

Navan, a travel and expense management company, has introduced a new artificial intelligence (AI) system called Navan Cognition, built to help companies create and manage full teams of AI workers.

In an announcement published on June 25, the platform connects several AI agents, each trained to perform a specific job.

This setup is supervised to catch serious mistakes before they cause problems. The goal is to keep the system reliable, especially during complex tasks.

ICO vs IDO vs IEO: Which One's the Best? (Easily Explained)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Ilan Twig, co-founder and CTO of Navan, said:

Navan Cognition makes it easy to design, test, and launch sophisticated multi-agent AI applications with simple, plain-language prompts and one-click deployment.

Navan Cognition has been used internally at Navan since 2023. Ava, an AI assistant powered by Navan Cognition, runs on the platform and handles daily support requests from customers. It assists with tasks such as processing refunds, canceling trips, upgrading seats, and resolving travel issues.

Currently, Navan plans to open the platform to other businesses. Companies will be able to build their own AI teams using plain instructions.

These teams can be set up, tested, and deployed with simple tools, without the need for technical skills. Managers will also be able to track performance and update their AI agents as needed.

Dr. Itamar Kahn, a neuroscience professor at Columbia University, praised the system’s ability to avoid serious errors while handling large volumes of sensitive tasks.

On June 23, Goldman Sachs announced that its in-house AI assistant will be made available to all employees. What did the company say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.

]]>
https://earlybirdsinvest.com/navans-new-ai-platform-lets-businesses-deploy-full-teams/feed/ 0 44885
How to Build and Deploy Smart Contracts on Ethereum: A Comprehensive Guide for Businesses https://earlybirdsinvest.com/how-to-build-and-deploy-smart-contracts-on-ethereum-a-comprehensive-guide-for-businesses/ https://earlybirdsinvest.com/how-to-build-and-deploy-smart-contracts-on-ethereum-a-comprehensive-guide-for-businesses/#respond Tue, 10 Jun 2025 23:59:42 +0000 https://earlybirdsinvest.com/how-to-build-and-deploy-smart-contracts-on-ethereum-a-comprehensive-guide-for-businesses/
Codezeros

Build and Deploy Smart Contracts

Smart contracts have rapidly gained traction as a core component of blockchain-based solutions, offering businesses a way to automate agreements, streamline processes, and create transparent, trustless transactions. As organizations explore the potential of blockchain, understanding how to build and deploy smart contracts on Ethereum becomes essential for those seeking efficiency, security, and innovation in their operations.

In this blog, we will walk you through the complete process of developing and deploying Ethereum smart contracts, highlighting key considerations, best practices, and the importance of working with a reputable Smart Contract Audit Company to minimize risks and maximize value.

A smart contract is a self-executing program stored on a blockchain that automatically enforces the terms of an agreement when predefined conditions are met. Unlike traditional contracts, which require manual intervention and are prone to disputes and delays, smart contracts execute instantly and impartially, reducing the need for intermediaries and minimizing operational risks.

Business Use Cases for Smart Contracts

  • Supply Chain Management: Automate tracking, payments, and inventory updates.
  • Insurance: Streamline claim processing and payouts.
  • Real Estate: Simplify property transfers and escrow arrangements.
  • Personal Identity: Securely manage digital identities and KYC processes

Ethereum is the most widely used blockchain for smart contract development due to its robust developer ecosystem, established standards, and support for complex decentralized applications (dApps). Ethereum smart contracts are typically written in Solidity, a contract-oriented programming language designed for the Ethereum Virtual Machine (EVM).

Before any code is written, clearly outline the objectives and requirements of your smart contract. Engage stakeholders to determine:

  • The specific business logic to automate
  • The parties involved and their roles
  • The data and assets to be managed
  • Security and compliance considerations

Building a secure smart contract requires a multidisciplinary team:

  • Blockchain developers proficient in Solidity
  • Security experts for code review and auditing
  • Project managers and business analysts
  • UI/UX designers (for dApp interfaces)

Several tools facilitate Ethereum smart contract development:

  • Remix IDE: A browser-based IDE for writing, testing, and deploying smart contracts.
  • Hardhat: A flexible development framework for compiling, testing, and deploying contracts.
  • Truffle: Another popular development suite for Ethereum.

Install Node.js and npm, then set up your preferred framework. For example, with Hardhat:

You’ll need an Ethereum wallet (such as MetaMask) to interact with the blockchain. For testing, use a test network (Goerli, Sepolia, etc.) and obtain test Ether from a faucet.

Here’s a simple example of a Solidity contract:

This contract allows users to store and retrieve a number.

Testing is crucial to catch bugs and vulnerabilities before deployment. Use the testing tools provided by your framework (Hardhat, Truffle, or Remix) to write unit and integration tests. Run your tests on a local blockchain or a public testnet.

Security is paramount. Engage a reputable Smart Contract Audit Company to conduct a thorough review of your code. Audits typically involve:

  • Automated testing for common vulnerabilities
  • Manual code review for logic errors and security flaws
  • Functional testing to ensure business logic is correctly implemented
  • Detailed reporting and recommendations for remediation

Smart contract audits are essential because deployed contracts are immutable; any errors or vulnerabilities can result in significant financial and reputational losses.

Once your contract passes all tests and audits, you’re ready to deploy. Deployment involves sending your compiled contract bytecode to the Ethereum network. This can be done using:

  • Remix IDE: Deploy directly from the browser.
  • Hardhat/Truffle: Use scripts to automate deployment.

Example with Hardhat:

After deployment, save your contract address for future interactions.

You can interact with your contract using:

  • Web interfaces (dApps) built with libraries like web3.js or ethers.js
  • Command-line scripts
  • Directly via wallets like MetaMask

Before any code is written, clearly outline the objectives and requirements of your smart contract. Engage stakeholders to determine:

  • The specific business logic to automate
  • The parties involved and their roles
  • The data and assets to be managed
  • Security and compliance considerations

Building a secure smart contract requires a multidisciplinary team:

  • Blockchain developers proficient in Solidity
  • Security experts for code review and auditing
  • Project managers and business analysts
  • UI/UX designers (for dApp interfaces)

Several tools facilitate Ethereum smart contract development:

  • Remix IDE: A browser-based IDE for writing, testing, and deploying smart contracts.
  • Hardhat: A flexible development framework for compiling, testing, and deploying contracts.
  • Truffle: Another popular development suite for Ethereum.

Install Node.js and npm, then set up your preferred framework. For example, with Hardhat:

You’ll need an Ethereum wallet (such as MetaMask) to interact with the blockchain. For testing, use a test network (Goerli, Sepolia, etc.) and obtain test Ether from a faucet.

Here’s a simple example of a Solidity contract:

This contract allows users to store and retrieve a number.

Testing is crucial to catch bugs and vulnerabilities before deployment. Use the testing tools provided by your framework (Hardhat, Truffle, or Remix) to write unit and integration tests. Run your tests on a local blockchain or a public testnet.

Security is paramount. Engage a reputable Smart Contract Audit Company to conduct a thorough review of your code. Audits typically involve:

  • Automated testing for common vulnerabilities
  • Manual code review for logic errors and security flaws
  • Functional testing to ensure business logic is correctly implemented
  • Detailed reporting and recommendations for remediation

Smart contract audits are essential because deployed contracts are immutable; any errors or vulnerabilities can result in significant financial and reputational losses.

Once your contract passes all tests and audits, you’re ready to deploy. Deployment involves sending your compiled contract bytecode to the Ethereum network. This can be done using:

  • Remix IDE: Deploy directly from the browser.
  • Hardhat/Truffle: Use scripts to automate deployment.

Example with Hardhat:

After deployment, save your contract address for future interactions.

You can interact with your contract using:

  • Web interfaces (dApps) built with libraries like web3.js or ethers.js
  • Command-line scripts
  • Directly via wallets like MetaMask
  • Follow Coding Standards: Adhere to established Solidity patterns and security guidelines.
  • Minimize Complexity: Simpler contracts are easier to audit and less prone to errors.
  • Use OpenZeppelin Libraries: Leverage well-tested libraries for common contract patterns (ERC20, ERC721, etc.).
  • Limit On-Chain Data: Store only essential data on-chain to reduce costs and improve efficiency.
  • Regularly Update Dependencies: Keep your development tools and libraries up to date.

A smart contract audit is a comprehensive review of your contract’s code to identify vulnerabilities, inefficiencies, and compliance issues. Audits help prevent exploits, ensure regulatory compliance, and boost your reputation among users and partners.

Key Steps in the Audit Process

  • Collect documentation and freeze the codebase
  • Conduct automated and manual testing
  • Classify and prioritize issues
  • Provide detailed reports and remediation guidance
  • Re-audit after fixes are applied
  • Reentrancy Attacks: Malicious contracts repeatedly call functions before previous executions are complete.
  • Integer Overflows/Underflows: Arithmetic errors leading to unexpected results.
  • Front-running: Attackers exploit transaction ordering for profit.
  • Denial of Service (DoS): Contracts are rendered unusable by malicious actors.
  • Access Control Issues: Unauthorized users gain access to restricted functions.

Before deploying to the Ethereum mainnet, thoroughly test your contract on public testnets like Goerli or Sepolia. This allows you to:

  • Validate contract functionality in a real blockchain environment
  • Identify network-specific issues
  • Gather feedback from stakeholders

Deploying on testnets is free and risk-free, as test Ether has no real value.

Once your contract is fully tested and audited, you can deploy to the mainnet. This step is irreversible, so double-check all parameters, addresses, and configurations. Monitor your contract post-deployment for unexpected behavior or interactions.

  • Monitor Transactions: Use block explorers (like Etherscan) to track contract activity and detect anomalies.
  • Plan for Upgrades: Immutable contracts cannot be changed, but upgradeability patterns (like proxy contracts) allow for future improvements.
  • Community Feedback: Encourage users to report bugs and suggest enhancements.

While it’s possible to build simple contracts independently, most businesses benefit from partnering with experienced smart contract development companies. These firms bring:

  • Deep expertise in blockchain architecture and security
  • Access to advanced development and auditing tools
  • Proven track record in delivering production-ready solutions
  • Ongoing support for upgrades, compliance, and integration

Building and deploying smart contracts on Ethereum opens up new possibilities for automating business processes, reducing costs, and increasing transparency. However, the process requires careful planning, robust development practices, and rigorous security audits to avoid costly mistakes.

If your business is considering adopting blockchain technology or developing smart contracts, working with a trusted partner is crucial for success.

Connect with Codezeros for expert Smart Contract Development and comprehensive audit services.

]]>
https://earlybirdsinvest.com/how-to-build-and-deploy-smart-contracts-on-ethereum-a-comprehensive-guide-for-businesses/feed/ 0 41311
Binance co-founder and Binance Charity to jointly deploy more than $1.5 million in assistance to Myanmar and Thailand in the aftermath of the earthquake https://earlybirdsinvest.com/binance-co-founder-and-binance-charity-to-jointly-deploy-more-than-1-5-million-in-assistance-to-myanmar-and-thailand-in-the-aftermath-of-the-earthquake/ https://earlybirdsinvest.com/binance-co-founder-and-binance-charity-to-jointly-deploy-more-than-1-5-million-in-assistance-to-myanmar-and-thailand-in-the-aftermath-of-the-earthquake/#respond Tue, 01 Apr 2025 17:45:44 +0000 https://earlybirdsinvest.com/binance-co-founder-and-binance-charity-to-jointly-deploy-more-than-1-5-million-in-assistance-to-myanmar-and-thailand-in-the-aftermath-of-the-earthquake/ Binance co-founders Changpeng Zhao and Binance Charity leveraged cryptocurrencies to facilitate rapid relief deployments in Myanmar and Thailand following the 7.7 magnitude earthquake.

The earthquake occurred in Mandalay, Myanmar’s second largest city, causing destruction and infrastructure damage. The same was true in Thailand. People felt the trembling of Bangkok, leading to a considerable number of casualties. Authorities have sued international aid as thousands have been injured, with 1,700 deaths reported so far.

On March 28, 2025, Zhao announced a personal donation of 1000 .CWP-Coin-Chart SVG Pass {Stroke width: 0.65! Important; }




















price









24 hours volume



?
->


Price 7d


is worth $630,000 to help support relief efforts in both affected countries.

The donations are evenly distributed, with 500 bnbs allocated to Myanmar and another 500 bnbs in Thailand. Zhao will use donated funds to support infrastructure redevelopment, medical assistance and emergency services. He commissioned Binance and Binance Thail to oversee the distribution of funds.

Zhao’s actions encourage others in the Crypto community to contribute to the ongoing relief efforts. For example, Anndy Lian, an intergovernmental blockchain advisor, has donated 44 BNB to organizations supporting Myanmar’s relief efforts.

Explore:CZ just burned millions with meme coins: Will Changpeng save your favorite shit?

Binance Charity launches Airdrop initiative

Complementing Zhao’s personal donations, Binance Charity has launched an Airdrop initiative to donate up to $1.5 million in BNB to affected people in Myanmar and Thailand. Through this initiative, Binance Charity hopes to provide financial support to those affected through Conking Your Consumer (KYC) and the Proof of Address (POA) protocol.

Eligible users can expect BNB tokens to appear in the Rewards Hub by April 14, 2025. The amounts received by each individual are based on the status and location of the verification.

According to the breakdown of the distribution provided by Binance, all KYC-enhanced non-dormant binance users in Myanmar receive $5 in BNB, while users with both KYC and POA validation in affected regions receive $50 in BNB.

Regarding Thailand, users who are verified with registered living addresses may receive $5 in BNB, but users will be verified at their hard hit zone address. By leveraging blockchain technology, this structured approach to decentralizing aid ensures that those who are most needy are released in a timely and secure way.

Explore: Tiger King launches Solana Meme coin from prison: Joe “Tiger” Exotic Stems Are His Code Prey?

The role of cryptocurrency in relief assistance

Cryptocurrencies are increasingly emerging as an essential tool for humanitarian assistance. Bank restrictions could delay traditional aid, but crypto donations are quick, transparent and bounded. This efficiency is essential for disaster scenarios where rapid and efficient deployment of aid can have a significant impact on recovery efforts.

Crypto has already introduced its potential during the Syrian Turkey (2023) and the Maui Wildfire (2023), and played a key role in quickly increasing funding and solidifying its position as a viable solution in emergencies.

To save children, Giving Block is a number of notable organizations that advocated blockchain donations to quickly and efficiently distribute financial assistance in disaster zones.

Explore: Hype prices and Ton’s Cryptographs Show Resilience to the Wide Market Slump

Key takeout

  • Zhao donated $60,000 to earthquake relief in Myanmar and Thailand on BNB

  • Binance Charity has launched a $1.5 million crypto airdrop for affected users.

  • Zhao’s donations are distributed evenly, allocating 500 bnbs to Myanmar and another 500 bnbs to Thailand.

Post-Vinance co-founder and Binance Charity, which will jointly deploy more than $1.5 million in aid to Myanmar and Thailand in the aftermath of the earthquake, first appeared in 99 Bitcoin.

]]>
https://earlybirdsinvest.com/binance-co-founder-and-binance-charity-to-jointly-deploy-more-than-1-5-million-in-assistance-to-myanmar-and-thailand-in-the-aftermath-of-the-earthquake/feed/ 0 28442
Microsoft says attackers use exposed ASP.NET keys to deploy malware https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/ https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/#respond Thu, 06 Feb 2025 22:55:26 +0000 https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/

Key

Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.

As Microsoft Threat Intelligence experts recently discovered, some developers use ASP.NET validationKey and decryptionKey keys (designed to protect ViewState from tampering and information disclosure) found on code documentation and repository platforms in their own software.

However, threat actors also use machine keys from publicly available sources in code injection attacks to create malicious ViewStates (used by ASP.NET Web Forms to control state and preserve pages) by attaching crafted message authentication code (MAC).

When loading the ViewStates sent via POST requests, the ASP.NET Runtime on the targeted server decrypts and validates the attackers’ maliciously crafted ViewState data because it uses the right keys, loads it into the worker process memory, and executes it.

This allows them to execute code remotely on the IIS server and deploy additional malicious payloads.

In one instance observed in December 2024, an unattributed attacker used a publicly known machine key to deliver the Godzilla post-exploitation framework, which comes with malicious command execution and shellcode injection capabilities, to a targeted Internet Information Services (IIS) web server.

ViewState code injection attack chain
ViewState code injection attack chain (Microsoft)

“Microsoft has since identified over 3,000 publicly disclosed keys that could be used for these types of attacks, which are called ViewState code injection attacks,” the company said on Thursday.

“Whereas many previously known ViewState code injection attacks used compromised or stolen keys that are often sold on dark web forums, these publicly disclosed keys could pose a higher risk because they are available in multiple code repositories and could have been pushed into development code without modification.”

To block such attacks, Microsoft recommends developers securely generate machine keys, not use default keys or keys found online, encrypt machineKey and connectionStrings elements to block access to plaintext secrets, upgrade apps to use ASP.NET 4.8 to enable Antimalware Scan Interface (AMSI) capabilities, and harden Windows Servers by using attack surface reduction rules such as Block Webshell creation for Servers.

Microsoft also shared detailed steps for removing or replacing ASP.NET keys in the web.config configuration file using either PowerShell or the IIS manager console and removed key samples from its public documentation to further discourage this insecure practice.

“If successful exploitation of publicly disclosed keys has occurred, rotating machine keys will not sufficiently address possible backdoors or persistence methods established by a threat actor or other post-exploitation activity, and additional investigation may be warranted,” Redmond warned.

“In particular, web-facing servers should be fully investigated and strongly considered for re-formatting and re-installation in an offline medium in cases where publicly disclosed keys have been identified, as these servers are most at risk of possible exploitation.”

]]>
https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/feed/ 0 17857