Flaws – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 30 Jun 2025 17:23:29 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Flaws – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Pixel camera app creators update Indigo to address its main flaws https://earlybirdsinvest.com/pixel-camera-app-creators-update-indigo-to-address-its-main-flaws/ https://earlybirdsinvest.com/pixel-camera-app-creators-update-indigo-to-address-its-main-flaws/#respond Mon, 30 Jun 2025 17:23:28 +0000 https://earlybirdsinvest.com/pixel-camera-app-creators-update-indigo-to-address-its-main-flaws/
The Indigo camera app running on an iPhone.

Joe Maring / Android Authority

TL;DR

  • The latest update to the new Project Indigo app disables super-resolution by default on many iPhones.
  • The changes appear aimed at reducing overheating and stability issues reported in early tests.
  • Other tweaks include thermal warning adjustments and lower capture rates on weaker devices.

When we tested Project Indigo last month, we were impressed with its lifelike photos, but the app also caused our iPhone 16 to run hot and freeze up. Indigo is built by two of the creators behind Google’s Pixel camera app, and now a fresh update (Version 10.2) has landed this week that appears to address these sorts of issues.

According to the release notes, the Indigo update disables super-resolution by default on the iPhone 14 Pro, 14 Pro Max, 15, and 15 Plus models. It also tweaks thermal warnings so they only appear when the device reaches a “critical” temperature state rather than earlier in the overheating process.

Other changes include quality fixes for multi-frame super-resolution in scenes with both bright and low dynamic range areas, as well as reduced photo capture rates on lower-performing devices to improve stability. Tech Previews are also now disabled while captures are processing, and the update rounds out with general bug fixes and improvements.

The Indigo camera app, displayed in the App Store on an iPhone.

Joe Maring / Android Authority

While the update doesn’t explicitly mention performance or overheating fixes, many of these adjustments seem aimed at reducing the app’s processing load and preventing the heat build-up that could be the cause of crashes.

There’s still no timeline for the Android version of Indigo, but the developers previously confirmed it is in the works.

Got a tip? Talk to us! Email our staff at news@androidauthority.com. You can stay anonymous or get credit for the info, it’s your choice.
]]>
https://earlybirdsinvest.com/pixel-camera-app-creators-update-indigo-to-address-its-main-flaws/feed/ 0 45002
Critical Fortinet flaws now exploited in Qilin ransomware attacks https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/ https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/#respond Fri, 06 Jun 2025 14:16:19 +0000 https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/

Qilin

The Qilin ransomware operation has recently joined attacks exploiting two Fortinet vulnerabilities that allow bypassing authentication on vulnerable devices and executing malicious code remotely.

Qilin (also tracked as Phantom Mantis) surfaced in August 2022 as a Ransomware-as-a-Service (RaaS) operation under the “Agenda” name and has since claimed responsibility for over 310 victims on its dark web leak site.

Its victim list also includes high-profile organizations, such as automotive giant Yangfeng, publishing giant Lee Enterprises, Australia’s Court Services Victoria, and pathology services provider Synnovis. The Synnovis incident impacted several major NHS hospitals in London, which forced them to cancel hundreds of appointments and operations.

Threat intelligence company PRODAFT, which spotted these new and partially automated Qilin ransomware attacks targeting several Fortinet flaws, also revealed that the threat actors are currently focusing on organizations from Spanish-speaking countries, but they expect the campaign to expand worldwide.

“Phantom Mantis recently launched a coordinated intrusion campaign targeting multiple organizations between May and June 2025. We assess with moderate confidence that initial access are being achieved by exploiting several FortiGate vulnerabilities, including CVE-2024-21762, CVE-2024-55591, and others,” PRODAFT says in a private flash alert shared with BleepingComputer.

“Our observations indicate a particular interest in Spanish-speaking countries, as reflected in the data presented in the table below. However, despite this regional focus, we assess that the group continues to select its targets opportunistically, rather than following a strict geographical or sector-based targeting pattern.”

PRODAFT Fortinet Qilin ransomware attacks

One of the flaws abused in this campaign, tracked as CVE-2024-55591, was also exploited as a zero-day by other threat groups to breach FortiGate firewalls as far back as November 2024. The Mora_001 ransomware operator has also used it to deploy the SuperBlack ransomware strain linked to the infamous LockBit cybercrime gang by Forescout researchers.

The second Fortinet vulnerability exploited in these Qilin ransomware attacks (CVE-2024-21762) was patched in February, with CISA adding it to its catalog of actively exploited security flaws and ordering federal agencies to secure their FortiOS and FortiProxy devices by February 16.

Almost a month later, the Shadowserver Foundation announced that it had found that nearly 150,000 devices were still vulnerable to CVE-2024-21762 attacks.

Fortinet security vulnerabilities are often exploited (frequently as zero days) in cyber espionage campaigns and for breaching corporate networks in ransomware attacks.

For instance, in February, Fortinet disclosed that the Chinese Volt Typhoon hacking group used two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to deploy the Coathanger custom remote access trojan (RAT) malware, which had been previously used to backdoor a Dutch Ministry of Defence military network.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/critical-fortinet-flaws-now-exploited-in-qilin-ransomware-attacks/feed/ 0 40476
CISA tags Broadcom Fabric OS, CommVault flaws as exploited in attacks https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/ https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/#respond Tue, 29 Apr 2025 14:57:48 +0000 https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/

CISA

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) is warning of Broadcom Brocade Fabric OS, Commvault web servers, and Qualitia Active! Mail clients vulnerabilities that are actively exploited in attacks.

The flaws were added yesterday to CISA’s ‘Known Exploited Vulnerabilities’ (KEV) catalog, with the Broadcom Brocade Fabric OS and Commvault flaws not previously tagged as exploited.

Broadcom Brocade Fabric OS is a specialized operating system that runs on the company’s Brocade Fibre Channel switches to manage and optimize storage area networks (SAN).

Earlier this month, Broadcom disclosed an arbitrary code execution flaw impacting Fabric OS versions 9.1.0 through 9.1.1d6, tracked under CVE-2025-1976.

While the flaw requires admin privileges to exploit, Broadcom says it has been actively exploited in attacks.

“This vulnerability can allow the user to execute any existing Fabric OS command or can also be used to modify the Fabric OS itself, including adding their own subroutines,” reads Broadcom’s bulletin.

“Even though achieving this exploit first requires valid access to a role with admin privileges, this vulnerability has been actively exploited in the field.”

CVE-2025-1976 was addressed with the release of Brocade Fabric OS 9.1.1d7. The latest branch, 9.2.0, is not impacted by this vulnerability.

The Commvault flaw, tracked under CVE-2025-3928, is an unspecified security problem that authenticated attackers can exploit remotely to plant webshells on target servers.

Commvault web servers are user-facing and API components of a backup system used by enterprises to protect and restore critical data.

Despite the requirements for authentication and exposure of the environment to the internet, the flaw is under active exploitation in the wild.

CVE-2025-3928 was fixed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.

The third flaw CISA added to KEV is CVE-2025-42599, a stack-based buffer overflow problem impacting all versions of Active! up to and including ‘BuildInfo: 6.60.05008561’ on all OS platforms.

Active! mail is a web-based email client widely used by government, financial, and IT service organizations in Japan.

The flaw was flagged as actively exploited last week by Japan’s CERT, while SMB providers and ISPs in the country also announced service outages caused by related exploitation activity.

Qualitia addressed the problem with the release of Active! Mail 6 BuildInfo: 6.60.06008562.

CISA has given impacted organizations until May 17, 2025, to apply fixes or available mitigations for CVE-2025-3928 and May 19, 2025, for the other two flaws.

]]>
https://earlybirdsinvest.com/cisa-tags-broadcom-fabric-os-commvault-flaws-as-exploited-in-attacks/feed/ 0 33458
New York Slaps Block with $40 Million Fine After Crypto Oversight Flaws https://earlybirdsinvest.com/new-york-slaps-block-with-40-million-fine-after-crypto-oversight-flaws/ https://earlybirdsinvest.com/new-york-slaps-block-with-40-million-fine-after-crypto-oversight-flaws/#respond Fri, 11 Apr 2025 09:33:36 +0000 https://earlybirdsinvest.com/new-york-slaps-block-with-40-million-fine-after-crypto-oversight-flaws/

Block Inc., the company behind the Cash App platform, has agreed to pay $40 million to settle claims brought by New York state regulators.

The New York Department of Financial Services (NYDFS) said the fine came after an investigation into how the company handled rules around anti-money laundering (AML) and cryptocurrency transactions.

According to Bloomberg, which reviewed the regulator’s consent order, NYDFS found several issues with how Cash App was run. The report said Block failed to properly check the background of its users and did not take enough steps to review risky Bitcoin
BTC


$81,994.38

transactions.

What is Monero? XMR Animated Explainer

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Block said it worked with NYDFS to resolve concerns linked to how Cash App used to handle compliance. However, the company did not admit it broke any rules.

Bloomberg noted that the two sides had been working on a settlement since 2024, based on documents filed with the US Securities and Exchange Commission (SEC).

The company, created by Jack Dorsey in 2009, continues to perform well despite the regulatory issues. At the end of 2024, Block reported a 4.5% increase in revenue compared to the previous year, which reached $6.03 billion.

Block’s payment systems processed $61.95 billion in the same period, a 10% increase in total volume. This growth shows the company’s services remain in high demand.

Meanwhile, CLS Global, a company that provides liquidity in crypto markets, was recently fined over $428,000 and banned from operating in US crypto markets. Why? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/new-york-slaps-block-with-40-million-fine-after-crypto-oversight-flaws/feed/ 0 30210
BaFin Bans Ethena’s USDe Token in Germany Over Approval Process Flaws https://earlybirdsinvest.com/bafin-bans-ethenas-usde-token-in-germany-over-approval-process-flaws/ https://earlybirdsinvest.com/bafin-bans-ethenas-usde-token-in-germany-over-approval-process-flaws/#respond Sat, 22 Mar 2025 09:47:35 +0000 https://earlybirdsinvest.com/bafin-bans-ethenas-usde-token-in-germany-over-approval-process-flaws/

Key Takeaways:

  • Experts suggest the suspension may drive crypto firms to innovate in risk management and streamline internal compliance—potentially setting new industry benchmarks.
  • The regulator’s intervention is seen not merely as a punitive measure but as a wake-up call to reassess operational resilience in the evolving digital asset landscape.
  • Market observers believe that such rigorous enforcement might restore investor confidence and encourage clearer standards across synthetic token markets.

BaFin, Germany’s financial regulator, banned all public sales of Ethena GmbH’s USDe token this week, citing flaws in the approval process and violations of the European Union’s Markets in Crypto-Assets Regulation (MiCAR).

The regulator outlined several immediate actions against Ethena GmbH to enforce the ban.

According to BaFin, the synthetic dollar token had been offered as an unregistered security in Germany, prompting the authority to restrict its operations without delay.

BaFin Orders Asset Freeze and Website Shutdown for USDe Token

In its announcement, BaFin instructed Ethena GmbH to freeze the reserve assets backing the USDe token and halt all new customer registrations.

The company must also shut down its website, and a special representative has been appointed to oversee compliance with these directives.

“The BaFin also has reasonable grounds to suspect that Ethena GmbH in Germany sells securities in the form of sUSDe tokens from Ethena OpCo. Ltd. without the required prospectus,” the regulator said.

“The USDe and sUSDe tokens are interconnected in such a way that investors can receive a sUSDe token in exchange for a USDe token,” it added.

Despite the prohibition on primary sales and issuance, secondary market trading of USDe remains unaffected by the ban.

BaFin identified “serious deficiencies” in Ethena GmbH’s approval process, including noncompliance with MiCAR’s capital and asset reserve requirements.

Ethena GmbH had been operating under a transitional provision that allows issuers of asset-referenced tokens to continue business while awaiting regulatory approval.

The company applied for authorization on July 29, 2024, a day before the deadline, and has been issuing USDe in Germany since June 28, 2024.

Currently, approximately 5.4 billion USDe tokens are in circulation, with a substantial portion issued outside Germany before MiCAR took effect.

To safeguard customer interests, BaFin has ordered the company’s asset reserves to block and restrict the authority of its managing directors over those funds.

Holders of USDe tokens cannot redeem them directly with Ethena GmbH, though trading on secondary markets continues as normal.

BaFin’s statement also raised concerns about the company issuing sUSDe tokens, suggesting they could constitute unregistered securities.

The tokens are linked to USDe, allowing investors to exchange them while receiving additional returns.

The regulator is now considering further enforcement actions, which could include a complete ban on the public offering of these securities.

BaFin is overseeing the authorization process in collaboration with the European Central Bank (ECB), the European Banking Authority (EBA), and the European Securities and Markets Authority (ESMA).

Further details will be provided upon completion of the licensing process.

Ethena Defends USDe Token Amid BaFin Ban

Following BaFin’s ban on USDe in Germany, Ethena Labs reassured users that redemptions remain unaffected through its British Virgin Islands-based entity, Ethena BVI Limited.

The company, addressing the situation on X, stated that while its German subsidiary’s MiCAR application was denied, USDe remains fully backed.

“We are disappointed by this decision but will continue evaluating alternative regulatory frameworks,” Ethena wrote.

The firm also dismissed claims that its assets were frozen, clarifying that all funds remain accessible.

It plans to update its terms in the coming week to reflect the regulatory developments.

Ethena’s regulatory challenges come as institutional interest grows.

Recent investments include a $20 million backing from MEXC and a 500,000 ENA token purchase by World Liberty Financial.

BaFin Tightens Oversight on Synthetic Assets Across Europe

BaFin’s decision reflects the regulator’s cautious approach towards crypto assets operating within Germany’s jurisdiction.

Its ban on Ethena’s USDe token highlights the tightening regulatory grip on stablecoins and synthetic dollar tokens in Germany and across Europe.

With MiCAR enforcement ramping up, stablecoin and synthetic asset issuers will face increased scrutiny over compliance with capital, reserve, and disclosure requirements.

The outcome of BaFin’s assessment of Ethena GmbH could set a precedent for how synthetic dollar tokens are regulated under MiCAR across the EU.

Frequently Asked Questions (FAQs)

Is BaFin’s ban of USDe actually protecting German innovation rather than hindering it?

Counterintuitively, yes. By enforcing strict compliance standards early, BaFin creates a more predictable environment where legitimate crypto projects can thrive without unfair competition from operators who bypass proper authorization channels.

Does this ban reflect MiCAR’s flexibility or its rigidity?

Neither—it demonstrates MiCAR’s intentional interpretative space. Germany’s interpretation reveals how the regulation creates room for national authorities to calibrate enforcement based on local market conditions and risk appetites.

Is this primarily about USDe’s technology or about EU regulatory sovereignty?

The latter. This action positions Europe as asserting regulatory independence from both American permissiveness and Chinese restriction, establishing a distinct “third way” in global crypto governance.

The post BaFin Bans Ethena’s USDe Token in Germany Over Approval Process Flaws appeared first on Cryptonews.

]]>
https://earlybirdsinvest.com/bafin-bans-ethenas-usde-token-in-germany-over-approval-process-flaws/feed/ 0 26563
Solana Has ‘Many Flaws’, Claims Crypto Fund Founder https://earlybirdsinvest.com/solana-has-many-flaws-claims-crypto-fund-founder/ https://earlybirdsinvest.com/solana-has-many-flaws-claims-crypto-fund-founder/#respond Thu, 13 Feb 2025 05:02:23 +0000 https://earlybirdsinvest.com/solana-has-many-flaws-claims-crypto-fund-founder/

In a thread shared on X, Justin Bons—Founder and Chief Investment Officer of Cyber Capital, a fund he describes as Europe’s oldest cryptocurrency fund—set out a pointed critique of the Solana blockchain. He accuses Solana of suffering from numerous flaws, including repeated network outages, centralizing pressures through demanding hardware requirements, and what he views as a non-deterministic model that sacrifices reliability for speed.

Solana Has Flaws, But Is Still Leading

Bons conceded that Solana had shown improvements over time—especially in addressing outages—yet emphasized that blockchains “should never go down,” even in experimental stages. He drew attention to a trend of “significant congestion events” resulting from network scheduling bugs and issues with the QUIC protocol, while also stressing that sandwiching and MEV (Maximal Extractable Value) remain an “unsolved problem” industry-wide.

Bons described Solana’s hardware demands as particularly burdensome: “The biggest hardware cost by far is RAM, with 256GB of EC memory! This costs thousands of dollars…” Although the high cost of staking further compounds these barriers, Bons acknowledged that it continues to maintain more than 1,400 validators.

He criticized what he regards as a “broken local fee market” leading to degraded user experiences but expressed optimism that these issues would be resolved this year. Regarding Solana’s non-deterministic design, Bons argued it creates “less than a 1% chance of a TX failure,” but labeled it a structural inefficiency and waste. He also questioned the continued sponsorship of validators by the Solana Foundation, noting that while it was valuable during Solana’s initial growth, “the time has come when this should be discontinued… SOL can stand on its own now.”

Even so, Bons made it clear that he has moved from being a critic to a “supporter,” asserting, “SOL is a permissionless & sufficiently decentralized blockchain… BTC & ETH cannot provide this service at scale. That is why SOL is eating their lunch & while carrying on the cypherpunk torch.”

The remarks prompted a direct response from Solana community developer João Mendonça, who highlighted that the blockchain’s frequent pursuit of performance sometimes leads to near-breaking challenges. Mendonça stated, “Solana is pushing every single limit known to this industry… it still has a >99.9% uptime with more than a year record of no stoppage of block production.”

He believes additional occasional “accidents” remain possible until the network has multiple software clients—currently, the majority of stake runs on a single client—yet he maintained that Solana has continued to evolve. Mendonça also addressed the perceived centralization, stressing that high hardware requirements do not necessarily impede users’ ability to run nodes for verifiability.

According to him, node configurations can be stripped down to more modest requirements for those who only need to track the chain, reducing barriers to broader participation. He noted that all major blockchains employ incentives similar to Solana’s Foundation-funded sponsorship program in order to help bootstrap validator networks, observing that the Solana Foundation Delegation Program (SFDP) already declined from around 20% to about 12% of total stake.

Bons replied by underscoring that, while the presence of multiple clients might indeed reduce future network downtime, such outages should not be excused. He also reiterated skepticism about Solana’s non-deterministic approach, arguing it leads to an “optimistic model instead of a deterministic one,” which he believes reduces transaction reliability.

Mendonça pushed back by suggesting that Solana’s design “prioritizes speed to the user, pain to the developer… just how it should be,” and that halting the system prevents potential state corruption when significant issues arise, at least until multiple clients can secure network redundancy.

At press time, SOL traded at $192.

Solana price
SOL price, 1-week chart | Source: SOLUSDT on TradingView.com

Featured image from Shutterstock, chart from TradingView.com

]]>
https://earlybirdsinvest.com/solana-has-many-flaws-claims-crypto-fund-founder/feed/ 0 19138