patches – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 22 Aug 2025 12:37:01 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 patches – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Apple patches iOS zero-day that put crypto wallets at risk via malicious images https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/ https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/#respond Fri, 22 Aug 2025 12:37:00 +0000 https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/

Apple released iOS 18.6.2 and iPadOS 18.6.2 on Aug. 20, 2025, along with macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8, to fix a zero-day in the ImageIO framework that was exploited in the wild.

Per Apple, processing a malicious image could corrupt memory, enabling code execution, and the company is aware of a report of use in an extremely sophisticated attack targeting specific individuals.

The flaw sits in ImageIO, the component that parses common image formats, which makes delivery via everyday channels, including messaging apps and web content, straightforward from an attacker’s perspective. As security outlets reported, the bug is tracked as CVE-2025-43300 and stems from an out-of-bounds write that Apple addressed with improved bounds checking.

The crypto angle is direct. Wallet owners often copy and paste recipient addresses, and many keep recovery phrases in screenshots or photo storage for convenience. Research this year documented families of mobile spyware and stealers that scan galleries using optical character recognition and exfiltrate images with seed phrases, as well as strains that monitor the clipboard to swap addresses during a transaction.

As Kaspersky reported, SparkCat and its successor SparkKitty used OCR to harvest seed phrases from photos on both iOS and Android, including samples observed on official app stores.

A compromise achieved through a booby-trapped image can, therefore, act as an initial foothold to enable gallery scraping for recovery phrases, surveillance of crypto app activity, and clipboard hijacking during on-chain transfers. Previous research on clipboard hijackers explains how address strings are silently replaced to redirect funds during copy-paste, a tactic long used by drainer operations.

The current incident also fits a pattern of high-value iOS exploit chains used against targeted users. In 2023, Citizen Lab documented a zero-click chain, dubbed Blastpass, used to deliver commercial spyware, demonstrating how image and message parsing bugs can be linked for device takeover without user interaction.

That historical baseline, coupled with Apple’s acknowledgment of real-world use in the present case, frames the risk for crypto users who rely on mobile devices as primary signing endpoints.

Impact spans recent iPhone models and iPads covered by iOS 18 and iPadOS 18, including iPhone XS and later, plus supported Macs on Sequoia, Sonoma, and Ventura. Users can verify protection by confirming iOS or iPadOS 18.6.2, macOS Sequoia 15.6.1, Sonoma 14.7.8, or Ventura 13.7.8 in Settings, then rebooting after installation.

Security outlets urged immediate updates following Apple’s release and disclosure.

For a crypto-savvy audience, the operational takeaway is to close exposure by updating and to reduce post-exploit blast radius by moving seed storage off photo libraries, reviewing app photo permissions, limiting clipboard access, and treating mobile wallets as hot environments with strict hygiene.

Apple’s notes state the root cause was an out-of-bounds write in ImageIO that is now mitigated with stricter bounds checks, and the company confirmed exploitation reports when shipping the patch.

Mentioned in this article
]]>
https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/feed/ 0 54551
Google patches new Chrome zero-day bug exploited in attacks https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/ https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/#respond Tue, 03 Jun 2025 11:09:32 +0000 https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/

Google Chrome

Google has released an emergency security update to fix the third Chrome zero-day vulnerability exploited in attacks since the start of the year.

“Google is aware that an exploit for CVE-2025-5419 exists in the wild,” the company warned in a security advisory published on Monday.

This high-severity vulnerability is caused by an out-of-bounds read and write weakness in Chrome’s V8 JavaScript engine, reported one week ago by Clement Lecigne and Benoît Sevens of Google’s Threat Analysis Group.

Google says the issue was mitigated one day later by a configuration change the company pushed to the Stable channel across all Chrome platforms.

On Monday, it also fixed the zero-day with the release of 137.0.7151.68/.69 for Windows/Mac and 137.0.7151.68 for Linux, versions that are rolling out to users in the Stable Desktop channel over the coming weeks.

While Chrome will automatically update when new security patches are available, users can speed up the process by going to the Chrome menu > Help > About Google Chrome, letting the update finish, and clicking the ‘Relaunch’ button to install it immediately.

Chrome 137.0.7151.69

​While Google has already confirmed that CVE-2025-5419 is being exploited in the wild, the company will not share additional information regarding these attacks until more users have patched their browsers.

“Access to bug details and links may be kept restricted until a majority of users are updated with a fix,” Google said. “We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

This is Google’s third Chrome zero-day vulnerability since the start of the year, with two more patched in March and May.

The first, a high-severity sandbox escape flaw (CVE-2025-2783) discovered by Kaspersky’s Boris Larin and Igor Kuznetsov, was used to deploy malware in espionage attacks targeting Russian government organizations and media outlets.

The company released another set of emergency security updates in May to patch a Chrome zero-day that could let attackers take over accounts following successful exploitation.

Last year, Google patched 10 zero-days that were either demoed during the Pwn2Own hacking competition or exploited in attacks.

Tines Needle

Manual patching is outdated. It’s slow, error-prone, and tough to scale.

Join Kandji + Tines on June 4 to see why old methods fall short. See real-world examples of how modern teams use automation to patch faster, cut risk, stay compliant, and skip the complex scripts.

]]>
https://earlybirdsinvest.com/google-patches-new-chrome-zero-day-bug-exploited-in-attacks/feed/ 0 39879
SAP patches second zero-day flaw exploited in recent attacks https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/ https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/#respond Wed, 14 May 2025 04:34:11 +0000 https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/

SAP

SAP has released patches to address a second vulnerability exploited in recent attacks targeting SAP NetWeaver servers as a zero-day.

The company issued security updates for this security flaw (CVE-2025-42999) on Monday, May 12, saying it was discovered while investigating zero-day attacks involving another unauthenticated file upload flaw (tracked as CVE-2025-31324) in SAP NetWeaver Visual Composer that was fixed in April.

“SAP is aware of and has been addressing vulnerabilities in SAP NETWEAVER Visual Composer,” a SAP spokesperson told BleepingComputer. “We ask all customers using SAP NETWEAVER to install these patches to protect themselves. The Security Notes can be found here: 3594142 & 3604119.”

ReliaQuest first detected the attacks exploiting CVE-2025-31324 as a zero-day in April, reporting that threat actors were uploading JSP web shells to public directories and the Brute Ratel red team tool after breaching customers’ systems through unauthorized file uploads on SAP NetWeaver. The hacked instances were fully patched, indicating the attackers used a zero-day exploit.

This malicious activity was also confirmed by cybersecurity firms watchTowr and Onapsis, who also observed the attackers uploading web shell backdoors on unpatched instances exposed online. Forescout’s Vedere Labs has linked some of these attacks to a Chinese threat actor it tracks as Chaya_004.

Onyphe CTO Patrice Auffret told BleepingComputer in late April that “Something like 20 Fortune 500/Global 500 companies are vulnerable, and many of them are compromised,” adding that there were 1,284 vulnerable instances exposed online at the time, 474 already compromised.

The Shadowserver Foundation is now tracking over 2040 SAP Netweaver servers exposed on the Internet and vulnerable to attacks.

Vulnerable SAP NetWeaver servers exposed online
Vulnerable SAP NetWeaver servers exposed online (Shadowserver Foundation)

New flaw also exploited in zero-day attacks

While SAP did not confirm that CVE-2025-42999 was exploited in the wild, Onapsis CTO Juan Pablo Perez-Etchegoyen told BleepingComputer that the threat actors were chaining both vulnerabilities in attacks since January.

“The attacks we observed during March 2025 (that started with basic proves back in January 2025) are actually abusing both, the lack of authentication (CVE-2025-31324) as well as the insecure de-serialization (CVE-2025-42999),” Perez-Etchegoyen told BleepingComputer.

“This combination allowed attackers to execute arbitrary commands remotely and without any type of privileges on the system. This residual risk is basically a de-serialization vulnerability only exploitable by users with VisualComposerUser role on the SAP target system.”

SAP admins are advised to immediately patch their NetWeaver instances and consider disabling the Visual Composer service if possible, as well as restrict access to metadata uploader services and monitor for suspicious activity on their servers.

Since the attacks started, CISA has added the CVE-2025-31324 flaw to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to secure their systems by May 20, as mandated by Binding Operational Directive (BOD) 22-01.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/sap-patches-second-zero-day-flaw-exploited-in-recent-attacks/feed/ 0 36110