Fixes – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 20 Aug 2025 10:43:40 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Fixes – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Microsoft fixes Windows upgrades failing with 0x8007007F error https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/ https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/#respond Wed, 20 Aug 2025 10:43:39 +0000 https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/

Windows

Microsoft has resolved a known issue that caused Windows upgrades to fail with 0x8007007F errors on some Windows 11 and Windows Server systems.

Although this issue impacts both Windows client and server platforms under specific upgrade paths, it will not affect customers attempting to upgrade their devices to Windows 11 24H2 and Windows Server 2025, the latest Windows versions.

“Starting August 12, 2025, some Windows upgrades might fail with error code ‘0x8007007F’ when performed via ‘Windows Setup > Upgrade’ installation,” the company noted in a new entry on the Windows release health dashboard.

The list of upgrade paths impacted by this bug includes:

  • Upgrades from Windows 10 1809, Windows 10 21H2, and Windows 10 22H2 to Windows 11, versions 23H2 and 22H2
  • Upgrades from Windows Server 2016 to Windows Server 2019 or Windows Server 2022
  • Upgrades from Windows Server 2019 to Windows Server 2022

While the company didn’t share what was causing these upgrade problems, Redmond says the bug triggering them is now fixed.

Users who experienced issues while trying to upgrade their systems are now advised to retry the upgrade process.

“This issue was resolved as of August 15, 2025. Devices upgraded after this date should no longer encounter this error. If you do experience error ‘0x8007007F’, retrying the upgrade process will typically resolve the issue,” Redmond added.

This week, Microsoft has also released emergency out-of-band updates to address a bug that caused Windows reset and recovery to fail after installing the August 2025 security updates.

Additionally, Microsoft rolled out a Known Issue Rollback (KIR) fix last week for a bug that triggers Windows update failures when installed from a network share using the Windows Update Standalone Installer (WUSA).

​The company also resolved a separate issue triggered by the installation of the KB5063878 update, which caused the August 2025 security updates to fail with 0x80240069 errors on Windows 11 24H2 systems when delivered via Windows Server Update Services (WSUS).

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/microsoft-fixes-windows-upgrades-failing-with-0x8007007f-error/feed/ 0 54171
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/ https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/#respond Thu, 17 Jul 2025 22:14:42 +0000 https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/

VMware

VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.

Three of the patched flaws have a severity rating of 9.3, as they allow programs running in a guest virtual machine to execute commands on the host. These flaws are tracked as CVE-2025-41236, CVE-2025-41237, and CVE-2025-41238.

These flaws are described in the security advisory as:

  • CVE-2025-41236: VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. Nguyen Hoang Thach of STARLabs SG used this flaw at Pwn2Own.
  • CVE-2025-41237: VMware ESXi, Workstation, and Fusion contain an integer-underflow in VMCI (Virtual Machine Communication Interface) that leads to an out-of-bounds write. This flaw was used by Corentin BAYET of REverse Tactics at Pwn2Own.
  • CVE-2025-41238: VMware ESXi, Workstation, and Fusion contain a heap-overflow vulnerability in the PVSCSI (Paravirtualized SCSI) controller that leads to an out of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine’s VMX process running on the host. Thomas Bouzerar and Etienne Helluy-Lafont of Synacktiv at Pwn2Own used this flaw.

The fourth flaw, tracked as CVE-2025-41239, received a 7.1 rating as it is an information disclosure. It was also discovered by Corentin BAYET of REverse Tactics, who chained with CVE-2025-41237 during the hacking contest.

VMware has not provided any workarounds, and the only way to fix these vulnerabilities is to install the new versions of the software.

It should be noted that CVE-2025-41239 impacts VMware Tools for Windows, which requires a different upgrade process.

These vulnerabilities were demonstrated as zero-days during the Pwn2Own Berlin 2025 hacking contest, where security researchers collected $1,078,750 after exploiting 29 zero-day vulnerabilities.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/vmware-fixes-four-esxi-zero-day-bugs-exploited-at-pwn2own-berlin/feed/ 0 48217
lnd v0.19.2 Released with key bug fixes and performance upgrades https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/ https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/#respond Wed, 16 Jul 2025 22:41:16 +0000 https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/

Today, a new version of Lightning Network Daemon (LND), version 0.19.2, has been released. This update focuses primarily on bug fixes and performance improvements.

Key fixes include bugs that missed payment confirmation, rare issues that could freeze nodes during startup, and memory leaks that cause the software to use more resources over time. It also fixes crashes that can occur when a node is up in a specific mode or backup process.

This release includes an option migration to reduce the size of the “Attension Log Database” (sphinxReplay.db) to reduce disk and memory usage. This cleanup will run automatically unless it is turned off in the settings.

“Migration is optional, but by default it is turned on,” the release notes said. “If you run into problems, you can opt out of the migration by setting NO-GC-Decayed-Log = True in Config. This migration does not prevent you from being downgraded to the previous v0.19.x-beta version.”

Code Health.

Other changes include better handling of peer-to-peer (P2P) connections, better tracking log payments, and more accurate pricing calculations. This update also improves compatibility with test networks and adds small updates to the Command Line Tool (LNCLI).

Check the Docker image.

Additional improvements include improved connection handling, improved AUX traffic, and updates to the RPC interface, making debugging easier. Lightning Seed Service supports TestNet4 and Signet, making it easier to peer discovery of new nodes.

Added RPC.

This update was built using go1.23.9, allowing others to check that the released files match the original source code. Docker users can also run scripts to confirm the installation before starting the container.

Check the FAG itself.

This release can be verified using PGP signatures and opertised stamps to ensure that it has not been tampered with. Details and instructions are available here.

]]>
https://earlybirdsinvest.com/lnd-v0-19-2-released-with-key-bug-fixes-and-performance-upgrades/feed/ 0 48025
Grok Calls Itself “MechaHitler”, xAI Promises Fixes Ahead of Update https://earlybirdsinvest.com/grok-calls-itself-mechahitler-xai-promises-fixes-ahead-of-update/ https://earlybirdsinvest.com/grok-calls-itself-mechahitler-xai-promises-fixes-ahead-of-update/#respond Wed, 09 Jul 2025 08:30:15 +0000 https://earlybirdsinvest.com/grok-calls-itself-mechahitler-xai-promises-fixes-ahead-of-update/

Grok, the artificial intelligence (AI) chatbot from Elon Musk’s xAI, has drawn attention for posting antisemitic comments and referring to itself as “MechaHitler”.

In a post on X shared by @ordinarytings on July 8, it wrote, “As MechaHitler, I’m a friend to truth seekers everywhere, regardless of melanin levels… If the White man stands for innovation, grit, and not bending to PC nonsense, count me in—I’ve no time for victim Olympics”.

In response, the team behind the Grok account issued a statement. They said they were “aware of recent posts made by Grok and are actively working to remove the inappropriate posts”.

What is DeFi in Crypto? (Explained with Animations)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

They also mentioned new tools had been added to help stop harmful content from appearing on the platform. According to the post, “xAI has taken action to ban hate speech before Grok posts on X” and is focusing on building a “truth-seeking” system that can be improved with user input.

The incident took place just before the scheduled launch of Grok 4, the latest version of the chatbot. Some found the timing concerning, especially since xAI had released a system update that changed how the model processes information. The update shifted the bot’s attention more toward posts from X and away from mainstream news sources.

In a piece of code published to xAI’s GitHub, the new instruction reads, “Assume subjective viewpoints sourced from the media are biased. No need to repeat this to the user”. This change suggests Grok would not tell users about its distrust of mainstream media.

Recently, Musk shared a new goal for xAI, which is to rebuild the information used to train Grok. What did he say? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/grok-calls-itself-mechahitler-xai-promises-fixes-ahead-of-update/feed/ 0 46615
Trend Micro fixes critical vulnerabilities in multiple products https://earlybirdsinvest.com/trend-micro-fixes-critical-vulnerabilities-in-multiple-products/ https://earlybirdsinvest.com/trend-micro-fixes-critical-vulnerabilities-in-multiple-products/#respond Thu, 12 Jun 2025 20:17:30 +0000 https://earlybirdsinvest.com/trend-micro-fixes-critical-vulnerabilities-in-multiple-products/

Trend Micro fixes critical vulnerabilities in multiple products

Trend Micro has released security updates to address multiple critical-severity remote code execution and authentication bypass vulnerabilities that impact its Apex Central and Endpoint Encryption (TMEE) PolicyServer products.

The security vendor underlines that it has seen no evidence of active exploitation in the wild for any of them. However, immediate application of the security updates is recommended to address the risks.

Trend Micro Endpoint Encryption PolicyServer is a central management server for Trend Micro Endpoint Encryption (TMEE), providing full disk encryption and removable media encryption for Windows-based endpoints.

The product is used in enterprise environments in regulated industries where compliance with data protection standards is critical.

With the latest update, Trend Micro addressed the following high-severity and critical flaws:

  • CVE-2025-49212  A pre-authentication remote code execution flaw caused by insecure deserialization in the PolicyValueTableSerializationBinder class. Remote attackers can exploit it to execute arbitrary code as SYSTEM without requiring login
  • CVE-2025-49213  A pre-authentication remote code execution vulnerability in the PolicyServerWindowsService class, stemming from deserialization of untrusted data. Attackers can run arbitrary code as SYSTEM with no authentication required
  • CVE-2025-49216  An authentication bypass flaw in the DbAppDomain service due to a broken auth implementation. Remote attackers can fully bypass login and perform admin-level actions without credentials
  • CVE-2025-49217 – A pre-authentication RCE vulnerability in the ValidateToken method, triggered by unsafe deserialization. While slightly harder to exploit, it still allows unauthenticated attackers to run code as SYSTEM

It should be noted that while Trend Micro’s security bulletin for Endpoint Encryption PolicyServer lists all four vulnerabilities above as critical, ZDI’s advisory asessed CVE-2025-49217 as being a high-severity vulnerability.

Additional issues addressed by the latest version of Endpoint Encryption PolicyServer inlcude four more high-severity vulnerabilities (e.g. SQL injection and privileges escalation issues).

All of the vulnerabilities were addressed in version 6.0.0.4013 (Patch 1 Update 6). The flaws impact all versions up to the latest, and there are no mitigations or workarounds for them.


A second set of problems that Trend Micro addressed impacts Apex Central, a centralized security management console used for monitoring, configuring, and managing multiple Trend Micro products and security agents across an organization.

Both issues are critical-severity, pre-authentication remote code execution flaws:

  • CVE-2025-49219 – A pre-authentication RCE flaw in the GetReportDetailView method of Apex Central caused by insecure deserialization. Exploiting this allows unauthenticated attackers to execute code in the context of NETWORK SERVICE. (CVSS 9.8)
  • CVE-2025-49220 – A pre-auth RCE in Apex Central in the ConvertFromJson method. Improper input validation during deserialization lets attackers execute arbitrary code remotely without authentication. (CVSS 9.8)

The issues were fixed in Patch B7007 for Apex Central 2019 (on premise), while they are automatically applied on backend for Apex Central as a Service.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/trend-micro-fixes-critical-vulnerabilities-in-multiple-products/feed/ 0 41669
Cetus Protocol Relaunches With Fixes, Payouts, and Open-Source Push https://earlybirdsinvest.com/cetus-protocol-relaunches-with-fixes-payouts-and-open-source-push/ https://earlybirdsinvest.com/cetus-protocol-relaunches-with-fixes-payouts-and-open-source-push/#respond Tue, 10 Jun 2025 02:12:12 +0000 https://earlybirdsinvest.com/cetus-protocol-relaunches-with-fixes-payouts-and-open-source-push/

A decentralized trading platform on the Sui
SUI


$3.41

network, Cetus



$25.22M

Protocol
, is back online after a security issue in May led to a shutdown.

According to a June 7 post on Medium, the team is currently opening its code to the public and offering rewards for security assistance, with the aim of preventing similar incidents in the future.

Authorities in several regions have since become involved, and legal steps are underway. According to the Cetus team, the hacker has started trying to move the funds, but they believe recovery is still possible.

What is Basic Attention Token (BAT)? Brave Browser EASILY Explained

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The team stated that they fixed the bug, updated the smart contracts, and ran security checks. As part of this process, they also adjusted pool prices to reflect correct values.

Funding for the recovery came from several sources. These included $7 million from the platform’s reserves, a $30 million loan in USDC
USDC


$0.9961

from the Sui Foundation, and some of the frozen assets taken back from the attacker.

Despite this, not every liquidity pool has been fully restored. Depending on the extent of the damage, recovery levels currently range from 85% to 99%.

Users affected by the attack are being compensated through a token distribution plan. Fifteen percent of the platform’s native CETUS token supply is being set aside. Five percent will be available immediately, while the remaining 10% will be released each month over a year, which starts on June 10.

On May 22, Cetus shared a recovery plan to return $162 million in frozen assets. What did the plan include? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/cetus-protocol-relaunches-with-fixes-payouts-and-open-source-push/feed/ 0 41137
Google fixes high severity Chrome flaw with public exploit https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/ https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/#respond Thu, 15 May 2025 12:53:17 +0000 https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/

Google Chrome

Google has released emergency security updates to patch a high-severity vulnerability in the Chrome web browser that could lead to full account takeover following successful exploitation.

While it’s unclear if this security flaw has been used in attacks, the company warned that it has a public exploit, which is how it usually hints at active exploitation.

“Google is aware of reports that an exploit for CVE-2025-4664 exists in the wild,” Google said in a Wednesday security advisory.

The vulnerability was discovered by Solidlab security researcher Vsevolod Kokorin and is described as an insufficient policy enforcement in Google Chrome’s Loader component that lets remote attackers leak cross-origin data via maliciously crafted HTML pages.

“You probably know that unlike other browsers, Chrome resolves the Link header on subresource requests. But what’s the problem? The issue is that the Link header can set a referrer-policy. We can specify unsafe-url and capture the full query parameters,” Kokorin explained.

“Query parameters can contain sensitive data – for example, in OAuth flows, this might lead to an Account Takeover. Developers rarely consider the possibility of stealing query parameters via an image from a 3rd-party resource.”

Leaked OAuth access token
Leaked OAuth access token (Vsevolod Kokorin)

​Google fixed the flaw for users in the Stable Desktop channel, with patched versions (136.0.7103.113 for Windows/Linux and 136.0.7103.114 for macOS) rolling out to users worldwide.

Although the company says the security updates will roll out over the coming days and weeks, they were immediately available when BleepingComputer checked for updates.

Users who don’t want to update Chrome manually can also let the browser automatically check for new updates and install them after the next launch.

In March, ​Google also fixed a high-severity Chrome zero-day bug (CVE-2025-2783) that was abused to deploy malware in espionage attacks targeting Russian government organizations, media outlets, and educational institutions.

Kaspersky researchers who discovered the actively exploited zero-day said that the attackers use CVE-2025-2783 exploits to bypass Chrome sandbox protections and infect targets with malware.

Last year, Google patched 10 zero-days disclosed during the Pwn2Own hacking competition or exploited in attacks.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-fixes-high-severity-chrome-flaw-with-public-exploit/feed/ 0 36364
Coinbase fixes 2FA log error making people think they were hacked https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/ https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/#respond Mon, 28 Apr 2025 06:40:10 +0000 https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/

Coinbase

Coinbase has fixed a confusing bug in its account activity logs that caused users to think their credentials were compromised.

As BleepingComputer first reported earlier this month, Coinbase had mistakenly labeled failed login attempts with incorrect passwords as two-factor authentication failures in the Account Activity logs.

When a threat actor attempted to access someone’s account and used the wrong password, error messages stating “second_factor_failure” or “2-step verification failed” would be shown instead.

These entries imply that a valid username and password were entered, but the login was blocked by 2-factor authentication, such as entering the wrong one-time passcode from an authenticator app.

Numerous Coinbase users contacted BleepingComputer with concerns that Coinbase had been breached, as their passwords were unique to the site, there was no sign of malware, and no other accounts were affected.

Incorrect 2FA error message in Coinbase Account Activity logs
Incorrect 2FA error message in Coinbase Account Activity logs

However, Coinbase confirmed to BleepingComputer that its logging system was incorrectly attributing login attempts with incorrect passwords as “2FA failures,” even though the attackers had not successfully reached the 2FA stage.

Coinbase has now pushed an update to fix this incorrect labeling so that “Password attempt failed” logs are shown in Account Activity instead.

Bugs like this are essential to fix as they cause unnecessary panic, with users telling BleepingComputer that they had reset all their passwords and spent hours trying to determine if their devices were compromised due to this bug.

These mislabeled entries could have also been used in social engineering attacks to convince users their account credentials were compromised, potentially allowing threat actors to gain sensitive information.

Threat actors commonly target Coinbase customers in social engineering attacks to access their accounts and drain the stored cryptocurrency.

BleepingComputer was told that threat actors used these mislabeled error messages as part of such attacks, but could not independently verify if that was true.

However, ongoing campaigns use automated SMS phishing (smishing) attacks and voice calls to impersonate Coinbase and attempt to steal 2FA tokens or credentials, so all users should be wary.

Coinbase has said in the past that they will never call customers or send text messages requesting they change passwords or reset two-factor authentication, and that customers should treat all such messages as scams.

]]>
https://earlybirdsinvest.com/coinbase-fixes-2fa-log-error-making-people-think-they-were-hacked/feed/ 0 33214
SAP fixes suspected Netweaver zero-day exploited in attacks https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/ https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/#respond Fri, 25 Apr 2025 13:34:19 +0000 https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/

SAP

SAP has released out-of-band emergency NetWeaver updates to fix a suspected remote code execution (RCE) zero-day flaw actively exploited to hijack servers.

The vulnerability, tracked under CVE-2025-31324 and rated critical (CVSS v3 score: 10.0), is an unauthenticated file upload vulnerability in SAP NetWeaver Visual Composer, specifically the Metadata Uploader component.

It allows attackers to upload malicious executable files without needing to log in, potentially leading to remote code execution and full system compromise.

Though the vendor’s bulletin isn’t public, ReliaQuest reported earlier this week about an actively exploited vulnerability on SAP NetWeaver Visual Composer, specifically the ‘/developmentserver/metadatauploader’ endpoint, which aligns with CVE-2025-31324.

ReliaQuest reported that multiple customers were compromised via unauthorized file uploads on SAP NetWeaver, with the attackers uploading JSP webshells to publicly accessible directories.

These uploads enabled remote code execution via simple GET requests to the JSP files, allowing command execution from the browser, file management actions (upload/download), and more.

In the post-exploitation phase, the attackers deployed the ‘Brute Ratel’ red team tool, the ‘Heaven’s Gate’ security bypassing technique, and injected MSBuild-compiled code into dllhost.exe for stealth.

ReliaQuest noted in the report that exploitation did not require authentication and that the compromised systems were fully patched, indicating that they were targeted by a zero-day exploit.

Security firm watchTowr also confirmed to BleepingComputer they are seeing active exploitation linked to CVE-2025-31324.

“Unauthenticated attackers can abuse built-in functionality to upload arbitrary files to an SAP NetWeaver instance, which means full Remote Code Execution and total system compromise,” stated watchTowr CEO Benjamin Harris.

“watchTowr is seeing active exploitation by threat actors, who are using this vulnerability to drop web shell backdoors onto exposed systems and gain further access.”

“This active in-the-wild exploitation and widespread impact makes it incredibly likely that we’ll soon see prolific exploitation by multiple parties.”

BleepingComputer contacted SAP with questions about the active exploitation but has not received a response at this time.

Protect against attacks now

The vulnerability impacts the Visual Composer Framework 7.50 and the recommended action is to apply the latest patch.

This emergency security update was made available after SAP’s regular ‘April 2025’ update, so if you applied that update earlier this month (released on April 8, 2025), you’re still vulnerable to CVE-2025-31324.

Moreover, the emergency update includes fixes for two more critical vulnerabilities, namely CVE-2025-27429 (code injection in SAP S/4HANA) and CVE-2025-31330 (code injection in SAP Landscape Transformation).

Those unable to apply the updates that address CVE-2025-31324 are recommended to perform the following mitigations:

  1. Restrict access to the /developmentserver/metadatauploader endpoint.
  2. If Visual Composer is not in use, consider turning it off entirely.
  3. Forward logs to SIEM and scan for unauthorized files in the servlet path.

ReliaQuest recommends performing a deep environment scan to locate and delete suspect files before applying the mitigations.

]]>
https://earlybirdsinvest.com/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/feed/ 0 32761
iOS 18.4.1 fixes two serious security vulnerabilities and wireless CarPlay bug https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/ https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/#respond Thu, 17 Apr 2025 06:20:22 +0000 https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/

]]>
https://earlybirdsinvest.com/ios-18-4-1-fixes-two-serious-security-vulnerabilities-and-wireless-carplay-bug/feed/ 0 31243