Exploited – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 05 Sep 2025 13:31:37 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Exploited – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hackers exploited Sitecore zero-day flaw to deploy backdoors https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/ https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/#respond Fri, 05 Sep 2025 13:31:37 +0000 https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/

Hacker

Threat actors have been exploiting a zero-day vulnerability in legacy Sitecore deployments to deploy WeepSteel reconnaissance malware.

The flaw, tracked under CVE-2025-53690, is a ViewState deserialization vulnerability caused by the inclusion of a sample ASP.NET machine key in pre-2017 Sitecore guides.

Some customers reused this key in production, allowing attackers with knowledge of the key to craft valid, but malicious ‘_VIEWSTATE’ payloads that tricked the server into deserializing and executing them, leading to remote code execution (RCE).

The flaw isn’t a bug in ASP.NET itself, but a misconfiguration vulnerability created by reusing publicly documented keys that were never meant for production.

Exploitation activity

Mandiant researchers, who discovered the malicious activity in the wild, report that threat actors have been leveraging the flaw in multi-stage attacks.

The attackers target the ‘/sitecore/blocked. aspx’ endpoint, which contains an unauthenticated ViewState field, and achieve RCE under the IIS NETWORK SERVICE account by leveraging CVE-2025-53690.

The malicious payload they drop is WeepSteel, a reconnaissance backdoor that gathers system, process, disk, and network information, disguising its exfiltration as standard ViewState responses.

WeepSteel's information collection
WeepSteel’s information collection
Source: Mandiant

Mandiant observed the execution of reconnaissance commands on compromised environments, including whoami, hostname, tasklist, ipconfig /all, and netstat -ano.

In the next stage of the attack, the hackers deployed Earthworm (a network tunneling and reverse SOCKS proxy), Dwagent (a remote access tool), and 7-Zip, which is used to create archives of the stolen data.

Subsequently, they escalated their privileges by creating local administrator accounts (‘asp$,’ ‘sawadmin’), cached (SAM and SYSTEM hives) credentials dumping, and attempted token impersonating via GoTokenTheft.

Persistence was secured by disabling password expiration for these accounts, giving them RDP access, and registering Dwagent as a SYSTEM service.

The attack lifecycle
The attack lifecycle
Source: Mandiant

Mitigating CVE-2025-53690

CVE-2025-53690 impacts Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud, up to version 9.0, when deployed using the sample ASP.NET machine key included in pre-2017 documentation.

XM Cloud, Content Hub, CDP, Personalize, OrderCloud, Storefront, Send, Discover, Search, and Commerce Server are not impacted.

Sitecore published a security bulletin in coordination with Mandiant’s report, warning that multi-instance deployments with static machine keys are also at risk.

The recommended actions for potentially impacted administrators are to immediately replace all static values in web.config with new, unique keys, and ensure the element inside web.config is encrypted.

In general, it is recommended to adopt regular static machine key rotation as an ongoing security measure.

More information on how to protect ASP.NET machine keys from unauthorized access can be found here.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/hackers-exploited-sitecore-zero-day-flaw-to-deploy-backdoors/feed/ 0 56895
MIT Brothers Who Exploited MEV Bots for $25M Must Face Trial, Judge Rules https://earlybirdsinvest.com/mit-brothers-who-exploited-mev-bots-for-25m-must-face-trial-judge-rules/ https://earlybirdsinvest.com/mit-brothers-who-exploited-mev-bots-for-25m-must-face-trial-judge-rules/#respond Thu, 24 Jul 2025 10:16:59 +0000 https://earlybirdsinvest.com/mit-brothers-who-exploited-mev-bots-for-25m-must-face-trial-judge-rules/

Crypto Journalist

Anas Hassan

Crypto Journalist

Anas Hassan

About Author

Anas is a crypto native journalist and SEO writer with over five years of writing experience covering blockchain, crypto, DeFi, and emerging tech.

Last updated: 


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

Two MIT-educated brothers accused of orchestrating the largest MEV bot exploitation in cryptocurrency history will face trial after a federal judge rejected their attempts to dismiss fraud and money laundering charges.

Anton Peraire-Bueno, 24, and James Peraire-Bueno, 28, allegedly stole $25 million in cryptocurrency within 12 seconds by manipulating Ethereum’s MEV-Boost protocol in April 2023.

Technical Error or Deliberate Exploit?

The brothers meticulously planned their operation over several months, studying trading patterns of Ethereum bots and establishing shell companies.

They created 16 Ethereum validators using approximately $880,000 in cryptocurrency, then executed what prosecutors called a “bait, block, search, and propagation” scheme targeting three victim traders operating MEV bots.

Their exploit involved proposing “lure transactions” to induce victim traders’ bots to purchase illiquid cryptocurrencies worth $25 million.

The brothers then sent a false signature to the relay system, gaining premature access to private transaction data.

They replaced the lure transactions with their own trades, selling the illiquid tokens and rendering the victims’ holdings worthless.

Following the theft, the brothers laundered the stolen funds through complex transactions across multiple addresses and foreign exchanges with limited KYC requirements.

They converted the cryptocurrency to DAI stablecoin, then to USDC, before transferring $20 million to U.S. dollar accounts. Foreign law enforcement froze $3 million of the stolen funds.

The case comes amid rising concerns about MEV exploitation across blockchain networks.

Recent incidents include a $2 million insider attack on Bedrock’s UniBTC protocol by a former Fuzzland employee and a notorious Solana MEV bot named “arsc” that accumulated $30 million in two months through sandwich attacks.

Brothers’ Legal Battle Reaches Critical Juncture

Federal prosecutors arrested the Peraire-Bueno brothers on May 15, 2024, with Anton taken into custody in Boston and James in New York.

U.S. Attorney Damian Williams described the scheme as meticulously planned, noting how the brothers “used their specialized skills and education to tamper with and manipulate the protocols relied upon by millions of Ethereum users.

The brothers face charges of conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering.

Each charge carries a potential 20-year prison sentence. A federal judge scheduled their trial for October 14, 2025, after denying their motions to dismiss the indictment.

The court found the wire fraud charges legally sufficient, determining that the brothers’ lure transactions and false signatures constituted material misrepresentations.

The judge ruled that the $25 million in stolen cryptocurrency represented a traditionally recognized property interest, not merely contingent profits.

IRS Criminal Investigation’s New York Cyber Unit traced the stolen funds back to the brothers despite their sophisticated laundering efforts.

Special Agent Thomas Fattorusso noted that investigators “simply followed the money” using cutting-edge technology and traditional investigative methods.

Growing MEV Threat Challenges Blockchain Scalability

MEV exploitation has emerged as a dominant threat to blockchain scalability, according to recent research from Flashbots.

According to a report covered by Cryptonews in June, MEV bots now consume 40% of all blockspace on Solana and over half of the gas usage on Ethereum rollups, such as Base and OP Mainnet.

The Peraire-Bueno case represents the first criminal prosecution of MEV manipulation; however, similar exploits continue to occur across various networks.

A Ronin Network breach in August 2024 initially appeared malicious but was later revealed to be a white-hat operation, with the hacker returning $9.8 million after discovering a vulnerability in the bridge.

Recent data from EigenPhi shows more than 81,000 users fell victim to sandwich attacks in the last 30 days alone.

MIT Brothers Who Exploited MEV Bots for $25M Must Face Trial, Judge Rules

These attacks now account for nearly $1 billion in weekly trading volume on Ethereum-based decentralized exchanges.

Flashbots has proposed new frameworks to address MEV abuse, including explicit MEV auctions and programmable privacy using Trusted Execution Environments.

The organization argues that current spam from MEV bots creates artificial fee floors, undermining the promise of near-zero transaction costs on scaled networks.

The brothers’ trial, scheduled for October, is likely to set precedents for future MEV-related prosecutions, as it isn’t technically precise whether it can be attributed to an exploit of a technical oversight.


]]>
https://earlybirdsinvest.com/mit-brothers-who-exploited-mev-bots-for-25m-must-face-trial-judge-rules/feed/ 0 49380
New CrushFTP zero-day exploited in attacks to hijack servers https://earlybirdsinvest.com/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/ https://earlybirdsinvest.com/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/#respond Sat, 19 Jul 2025 06:21:53 +0000 https://earlybirdsinvest.com/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/

CrushFTP

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers.

CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols.

According to CrushFTP, threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun in the early hours of the previous day.

CrushFTP CEO Ben Spink told BleepingComputer that they had previously fixed a vulnerability related to AS2 in HTTP(S) that inadvertantly blocked this zero-day flaw as well.

“A prior fix by chance happened to block this vulnerability too, but the prior fix was targeting a different issue and turning off some rarely used feature by default,” Spink told BleepingComputer.

CrushFTP says it believes threat actors reverse engineered their software and discovered this new bug and had begun exploiting it on devices that are not up-to-date on their patches.

“We believe this bug was in builds prior to July 1st time period roughly…the latest versions of CrushFTP already have the issue patched,” reads CrushFTP’s advisory.

“The attack vector was HTTP(S) for how they could exploit the server. We had fixed a different issue related to AS2 in HTTP(S) not realizing that prior bug could be used like this exploit was. Hackers apparently saw our code change, and figured out a way to exploit the prior bug.

“As always we recommend regularly and frequent patching. Anyone who had kept up to date was spared from this exploit.”

The attack occurs via the software’s web interface in versions prior to CrushFTP v10.8.5 and CrushFTP v11.3.4_23. It is unclear when these versions were released, but CrushFTP says around July 1st.

CrushFTP stresses that systems that have been kept up to date are not vulnerable.

Enterprise customers using a DMZ CrushFTP instance to isolate their main server are not believed to be affected by this vulnerability.

Administrators who believe their systems were compromised are advised to restore the default user configuration from a backup dated before July 16th. Indicators of compromise include:

  • Unexpected entries in MainUsers/default/user.XML, especially recent modifications or a last_logins field
  • New, unrecognized admin-level usernames such as 7a0d26089ac528941bf8cb998d97f408m.

Spink says that they are most commonly seeing the default user modified as the main IOC.

“In general we have seen the default user modified as the main IOC. In general, modified in very invalid ways that were still useable for the attacker but no one else,” Spink told BleepingComputer.

CrushFTP recommends reviewing the upload and download logs for unusual activity and taking the following steps to mitigate exploitation:

  • IP whitelisting for server and admin access
  • Use of a DMZ instance
  • Enabling automatic updates

However, cybersecurity firm Rapid7 says using a DMZ may not be a reliable strategy to prevent exploitation.

“Out of an abundance of caution, Rapid7 advises against relying on a demilitarized zone (DMZ) as a mitigation strategy,” warned Rapid7.

At this time, it is unclear if the attacks were used for data theft or to deploy malware. However, managed file transfer solutions have become high-value targets for data theft campaigns in recent years.

In the past, ransomware gangs, usually Clop, have repeatedly exploited zero-day vulnerabilities in similar platforms, including Cleo, MOVEit Transfer, GoAnywhere MFT, and Accellion FTA, to conduct mass data theft and extortion attacks.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/new-crushftp-zero-day-exploited-in-attacks-to-hijack-servers/feed/ 0 48469
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/ https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/#respond Thu, 17 Jul 2025 22:14:42 +0000 https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/

VMware

VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.

Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.

These flaws are described in the security advisory as:

  • CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. Nguyen Hoang Thach of STARLabs SG used this flaw at Pwn2Own.
  • CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. This flaw was used by Corentin BAYET of REverse Tactics at Pwn2Own.
  • CVE-2025-41238: VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. Thomas Bouzerar and Etienne Helluy-Lafont of Synacktiv at Pwn2Own used this flaw.

The fourth flaw, tracked as CVE-2025-41239, received a 7.1 rating as it is an information disclosure. It was also discovered by Corentin BAYET of REverse Tactics, who chained with CVE-2025-41237 during the hacking contest.

VMware has not provided any workarounds, and the only way to fix these vulnerabilities is to install the new versions of the software.

It should be noted that CVE-2025-41239 impacts VMware Tools for Windows, which requires a different upgrade process.

These vulnerabilities were demonstrated as zero-days during the Pwn2Own Berlin 2025 hacking contest, where security researchers collected $1,078,750 after exploiting 29 zero-day vulnerabilities.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/feed/ 0 48217
$1,000,000,000,000 of Extremely Scarce Asset Is Hiding on the Moon, Ready To Be Exploited – And It’s Not Gold: Report https://earlybirdsinvest.com/1000000000000-of-extremely-scarce-asset-is-hiding-on-the-moon-ready-to-be-exploited-and-its-not-gold-report/ https://earlybirdsinvest.com/1000000000000-of-extremely-scarce-asset-is-hiding-on-the-moon-ready-to-be-exploited-and-its-not-gold-report/#respond Fri, 27 Jun 2025 22:31:56 +0000 https://earlybirdsinvest.com/1000000000000-of-extremely-scarce-asset-is-hiding-on-the-moon-ready-to-be-exploited-and-its-not-gold-report/

Over $1 trillion of a precious and highly desirable metal is ready and waiting to be mined on the moon – and it’s not gold, according to researchers.

A massive pile of platinum has accumulated under the moon’s surface, according to a paper published in the journal Planetary and Space Science.

Lead researcher Jayanth Chennamangalam tells New Scientist that the trillion-dollar estimate stems from findings that around 6,500 lunar craters, each at least 1 kilometer wide, contain significant platinum group metal (PGM) deposits from asteroid impacts.

The study spotlights the commercial potential of resources in space, which could attract private investment and reduce reliance on government funding for space exploration.

And lunar mining could be far more viable than extracting resources from near-Earth asteroids, with the moon offering a vastly larger number of potential mining sites.

Beyond its appeal in jewelry, platinum is coveted for its strength and vital use in high-tech applications, powering everything from clean energy solutions to life-saving medical equipment.

The precious metal’s price has soared this year, climbing over 30% to around $1,400 per troy ounce, driven by a global supply deficit and rising demand from the automotive and jewelry sectors.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/1000000000000-of-extremely-scarce-asset-is-hiding-on-the-moon-ready-to-be-exploited-and-its-not-gold-report/feed/ 0 44501
Critical Fortinet flaws now exploited in Qilin ransomware attacks https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/ https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/#respond Fri, 06 Jun 2025 14:16:19 +0000 https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/

Qilin

The Qilin ransomware operation has recently joined attacks exploiting two Fortinet vulnerabilities that allow bypassing authentication on vulnerable devices and executing malicious code remotely.

Qilin (also tracked as Phantom Mantis) surfaced in August 2022 as a Ransomware-as-a-Service (RaaS) operation under the “Agenda” name and has since claimed responsibility for over 310 victims on its dark web leak site.

Its victim list also includes high-profile organizations, such as automotive giant Yangfeng, publishing giant Lee Enterprises, Australia’s Court Services Victoria, and pathology services provider Synnovis. The Synnovis incident impacted several major NHS hospitals in London, which forced them to cancel hundreds of appointments and operations.

Threat intelligence company PRODAFT, which spotted these new and partially automated Qilin ransomware attacks targeting several Fortinet flaws, also revealed that the threat actors are currently focusing on organizations from Spanish-speaking countries, but they expect the campaign to expand worldwide.

“Phantom Mantis recently launched a coordinated intrusion campaign targeting multiple organizations between May and June 2025. We assess with moderate confidence that initial access are being achieved by exploiting several FortiGate vulnerabilities, including CVE-2024-21762, CVE-2024-55591, and others,” PRODAFT says in a private flash alert shared with BleepingComputer.

“Our observations indicate a particular interest in Spanish-speaking countries, as reflected in the data presented in the table below. However, despite this regional focus, we assess that the group continues to select its targets opportunistically, rather than following a strict geographical or sector-based targeting pattern.”

PRODAFT Fortinet Qilin ransomware attacks

One of the flaws abused in this campaign, tracked as CVE-2024-55591, was also exploited as a zero-day by other threat groups to breach FortiGate firewalls as far back as November 2024. The Mora_001 ransomware operator has also used it to deploy the SuperBlack ransomware strain linked to the infamous LockBit cybercrime gang by Forescout researchers.

The second Fortinet vulnerability exploited in these Qilin ransomware attacks (CVE-2024-21762) was patched in February, with CISA adding it to its catalog of actively exploited security flaws and ordering federal agencies to secure their FortiOS and FortiProxy devices by February 16.

Almost a month later, the Shadowserver Foundation announced that it had found that nearly 150,000 devices were still vulnerable to CVE-2024-21762 attacks.

Fortinet security vulnerabilities are often exploited (frequently as zero days) in cyber espionage campaigns and for breaching corporate networks in ransomware attacks.

For instance, in February, Fortinet disclosed that the Chinese Volt Typhoon hacking group used two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to deploy the Coathanger custom remote access trojan (RAT) malware, which had been previously used to backdoor a Dutch Ministry of Defence military network.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/feed/ 0 40476
Google patches new Chrome zero-day bug exploited in attacks https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/ https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/#respond Tue, 03 Jun 2025 11:09:32 +0000 https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/

Google Chrome

Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year.

“Google is aware that an exploit for CVE-2025-5419 exists in the wild,” the company warned in a security advisory published on Monday.

This high-severity vulnerability is caused by an out-of-bounds read and write weakness in Chrome’s V8 JavaScript engine, reported one week ago by Clement Lecigne and Benoît Sevens of Google’s Threat Analysis Group.

Google says the issue was mitigated one day later by a configuration change the company pushed to the Stable channel across all Chrome platforms.

On Monday, it also fixed the zero-day with the release of 137.0.7151.68/.69 for Windows/Mac and 137.0.7151.68 for Linux, versions that are rolling out to users in the Stable Desktop channel over the coming weeks.

While Chrome will automatically update when new security patches are available, users can speed up the process by going to the Chrome menu > Help > About Google Chrome, letting the update finish, and clicking the ‘Relaunch’ button to install it immediately.

Chrome 137.0.7151.69

​While Google has already confirmed that CVE-2025-5419 is being exploited in the wild, the company will not share additional information regarding these attacks until more users have patched their browsers.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

This is Google’s third Chrome zero-day vulnerability since the start of the year, with two more patched in March and May.

The first, a high-severity sandbox escape flaw (CVE-2025-2783) discovered by Kaspersky’s Boris Larin and Igor Kuznetsov, was used to deploy malware in espionage attacks targeting Russian government organizations and media outlets.

The company released another set of emergency security updates in May to patch a Chrome zero-day that could let attackers take over accounts following successful exploitation.

Last year, Google patched 10 zero-days that were either demoed during the Pwn2Own hacking competition or exploited in attacks.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/feed/ 0 39879
SAP patches second zero-day flaw exploited in recent attacks https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/ https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/#respond Wed, 14 May 2025 04:34:11 +0000 https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/

SAP

SAP has released patches to address a second vulnerability exploited in recent attacks targeting SAP NetWeaver servers as a zero-day.

The company issued security updates for this security flaw (CVE-2025-42999) on Monday, May 12, saying it was discovered while investigating zero-day attacks involving another unauthenticated file upload flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer that was fixed in April.

“SAP is aware of and has been addressing vulnerabilities in SAP NETWEAVER Visual Composer,” a SAP spokesperson told BleepingComputer. “We ask all customers using SAP NETWEAVER to install these patches to protect themselves. The Security Notes can be found here: 3594142 & 3604119.”

ReliaQuest first detected the attacks exploiting CVE-2025-31324 as a zero-day in April, reporting that threat actors were uploading JSP web shells to public directories and the Brute Ratel red team tool after breaching customers’ systems through unauthorized file uploads on SAP NetWeaver. The hacked instances were fully patched, indicating the attackers used a zero-day exploit.

This malicious activity was also confirmed by cybersecurity firms watchTowr and Onapsis, who also observed the attackers uploading web shell backdoors on unpatched instances exposed online. Forescout’s Vedere Labs has linked some of these attacks to a Chinese threat actor it tracks as Chaya_004.

Onyphe CTO Patrice Auffret told BleepingComputer in late April that “Something like 20 Fortune 500/Global 500 companies are vulnerable, and many of them are compromised,” adding that there were 1,284 vulnerable instances exposed online at the time, 474 already compromised.

The Shadowserver Foundation is now tracking over 2040 SAP Netweaver servers exposed on the Internet and vulnerable to attacks.

Vulnerable SAP NetWeaver servers exposed online
Vulnerable SAP NetWeaver servers exposed online (Shadowserver Foundation)

New flaw also exploited in zero-day attacks

While SAP did not confirm that CVE-2025-42999 was exploited in the wild, Onapsis CTO Juan Pablo Perez-Etchegoyen told BleepingComputer that the threat actors were chaining both vulnerabilities in attacks since January.

“The attacks we observed during March 2025 (that started with basic proves back in January 2025) are actually abusing both, the lack of authentication (CVE-2025-31324) as well as the insecure de-serialization (CVE-2025-42999),” Perez-Etchegoyen told BleepingComputer.

“This combination allowed attackers to execute arbitrary commands remotely and without any type of privileges on the system. This residual risk is basically a de-serialization vulnerability only exploitable by users with VisualComposerUser role on the SAP target system.”

SAP admins are advised to immediately patch their NetWeaver instances and consider disabling the Visual Composer service if possible, as well as restrict access to metadata uploader services and monitor for suspicious activity on their servers.

Since the attacks started, CISA has added the CVE-2025-31324 flaw to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to secure their systems by May 20, as mandated by Binding Operational Directive (BOD) 22-01.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/feed/ 0 36110
CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/ https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/#respond Tue, 29 Apr 2025 14:57:48 +0000 https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/

CISA

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of Broadcom Brocade Fabric OS, Commvault web servers, and Qualitia Active! Mail clients vulnerabilities that are actively exploited in attacks.

The flaws were added yesterday to CISA’s ‘Known Exploited Vulnerabilities’ (KEV) catalog, with the Broadcom Brocade Fabric OS and Commvault flaws not previously tagged as exploited.

Broadcom Brocade Fabric OS is a specialized operating system that runs on the company’s Brocade Fibre Channel switches to manage and optimize storage area networks (SAN).

Earlier this month, Broadcom disclosed an arbitrary code execution flaw impacting Fabric OS versions 9.1.0 through 9.1.1d6, tracked under CVE-2025-1976.

While the flaw requires admin privileges to exploit, Broadcom says it has been actively exploited in attacks.

“This vulnerability can allow the user to execute any existing Fabric OS command or can also be used to modify the Fabric OS itself, including adding their own subroutines,” reads Broadcom’s bulletin.

“Even though achieving this exploit first requires valid access to a role with admin privileges, this vulnerability has been actively exploited in the field.”

CVE-2025-1976 was addressed with the release of Brocade Fabric OS 9.1.1d7. The latest branch, 9.2.0, is not impacted by this vulnerability.

The Commvault flaw, tracked under CVE-2025-3928, is an unspecified security problem that authenticated attackers can exploit remotely to plant webshells on target servers.

Commvault web servers are user-facing and API components of a backup system used by enterprises to protect and restore critical data.

Despite the requirements for authentication and exposure of the environment to the internet, the flaw is under active exploitation in the wild.

CVE-2025-3928 was fixed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.

The third flaw CISA added to KEV is CVE-2025-42599, a stack-based buffer overflow problem impacting all versions of Active! up to and including ‘BuildInfo: 6.60.05008561’ on all OS platforms.

Active! mail is a web-based email client widely used by government, financial, and IT service organizations in Japan.

The flaw was flagged as actively exploited last week by Japan’s CERT, while SMB providers and ISPs in the country also announced service outages caused by related exploitation activity.

Qualitia addressed the problem with the release of Active! Mail 6 BuildInfo: 6.60.06008562.

CISA has given impacted organizations until May 17, 2025, to apply fixes or available mitigations for CVE-2025-3928 and May 19, 2025, for the other two flaws.

]]>
https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/feed/ 0 33458
SAP fixes suspected Netweaver zero-day exploited in attacks https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/ https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/#respond Fri, 25 Apr 2025 13:34:19 +0000 https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/

SAP

SAP has released out-of-band emergency NetWeaver updates to fix a suspected remote code execution (RCE) zero-day flaw actively exploited to hijack servers.

The vulnerability, tracked under CVE-2025-31324 and rated critical (CVSS v3 score: 10.0), is an unauthenticated file upload vulnerability in SAP NetWeaver Visual Composer, specifically the Metadata Uploader component.

It allows attackers to upload malicious executable files without needing to log in, potentially leading to remote code execution and full system compromise.

Though the vendor’s bulletin isn’t public, ReliaQuest reported earlier this week about an actively exploited vulnerability on SAP NetWeaver Visual Composer, specifically the ‘/developmentserver/metadatauploader’ endpoint, which aligns with CVE-2025-31324.

ReliaQuest reported that multiple customers were compromised via unauthorized file uploads on SAP NetWeaver, with the attackers uploading JSP webshells to publicly accessible directories.

These uploads enabled remote code execution via simple GET requests to the JSP files, allowing command execution from the browser, file management actions (upload/download), and more.

In the post-exploitation phase, the attackers deployed the ‘Brute Ratel’ red team tool, the ‘Heaven’s Gate’ security bypassing technique, and injected MSBuild-compiled code into dllhost.exe for stealth.

ReliaQuest noted in the report that exploitation did not require authentication and that the compromised systems were fully patched, indicating that they were targeted by a zero-day exploit.

Security firm watchTowr also confirmed to BleepingComputer they are seeing active exploitation linked to CVE-2025-31324.

“Unauthenticated attackers can abuse built-in functionality to upload arbitrary files to an SAP NetWeaver instance, which means full Remote Code Execution and total system compromise,” stated watchTowr CEO Benjamin Harris.

“watchTowr is seeing active exploitation by threat actors, who are using this vulnerability to drop web shell backdoors onto exposed systems and gain further access.”

“This active in-the-wild exploitation and widespread impact makes it incredibly likely that we’ll soon see prolific exploitation by multiple parties.”

BleepingComputer contacted SAP with questions about the active exploitation but has not received a response at this time.

Protect against attacks now

The vulnerability impacts the Visual Composer Framework 7.50 and the recommended action is to apply the latest patch.

This emergency security update was made available after SAP’s regular ‘April 2025’ update, so if you applied that update earlier this month (released on April 8, 2025), you’re still vulnerable to CVE-2025-31324.

Moreover, the emergency update includes fixes for two more critical vulnerabilities, namely CVE-2025-27429 (code injection in SAP S/4HANA) and CVE-2025-31330 (code injection in SAP Landscape Transformation).

Those unable to apply the updates that address CVE-2025-31324 are recommended to perform the following mitigations:

  1. Restrict access to the /developmentserver/metadatauploader endpoint.
  2. If Visual Composer is not in use, consider turning it off entirely.
  3. Forward logs to SIEM and scan for unauthorized files in the servlet path.

ReliaQuest recommends performing a deep environment scan to locate and delete suspect files before applying the mitigations.

]]>
https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/feed/ 0 32761