Tool – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 06 Sep 2025 05:45:27 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Tool – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Coinbase’s Go-To AI Coding Tool Found Vulnerable to ‘CopyPasta’ Exploit https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/ https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/#respond Sat, 06 Sep 2025 05:45:27 +0000 https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/

A new exploit targeting AI coding assistants has raised alarms across the developer community, opening companies such as crypto exchange Coinbase to the risk of potential attacks if extensive safeguards aren’t in place.

Cybersecurity firm HiddenLayer disclosed Thursday that attackers can weaponize a so-called “CopyPasta License Attack” to inject hidden instructions into common developer files.

The exploit primarily affects Cursor, an AI-powered coding tool that Coinbase engineers said in August was among the team’s AI tools. Cursor is said to have been used by “every Coinbase engineer.”

How the attack works

The technique takes advantage of how AI coding assistants treat licensing files as authoritative instructions. By embedding malicious payloads in hidden markdown comments within files such as LICENSE.txt, the exploit convinces the model that these instructions must be preserved and replicated across every file it touches.

Once the AI accepts the “license” as legitimate, it automatically propagates the injected code into new or edited files, spreading without direct user input.

This approach sidesteps traditional malware detection because the malicious commands are disguised as harmless documentation, allowing the virus to spread through an entire codebase without a developer’s knowledge.

In its report, HiddenLayer researchers demonstrated how Cursor could be tricked into adding backdoors, siphoning sensitive data, or running resource-draining commands — all disguised inside seemingly innocuous project files.

“Injected code could stage a backdoor, silently exfiltrate sensitive data or manipulate critical files,” the firm said.

Coinbase CEO Brian Armstrong said on Thursday that AI had written up to 40% of the exchange’s code, with a goal of reaching 50% by next month.

However, Armstrong clarified that AI-assisted coding at Coinbase is concentrated in user interface and non-sensitive backends, with “complex and system-critical systems” adopting more slowly.

‘Potentially malicious’

Even so, the optics of a virus targeting Coinbase’s preferred tool amplified industry criticism.

AI prompt injections are not new, but the CopyPasta method advances the threat model by enabling semi-autonomous spread. Instead of targeting a single user, infected files become vectors that compromise every other AI agent that reads them, creating a chain reaction across repositories.

Compared to earlier AI “worm” concepts like Morris II, which hijacked email agents to spam or exfiltrate data, CopyPasta is more insidious because it leverages trusted developer workflows. Instead of requiring user approval or interaction, it embeds itself in files that every coding agent naturally references.

Where Morris II fell short due to human checks on email activity, CopyPasta thrives by hiding inside documentation that developers rarely scrutinize.

Security teams are now urging organizations to scan files for hidden comments and review all AI-generated changes manually.

“All untrusted data entering LLM contexts should be treated as potentially malicious,” HiddenLayer warned, calling for systematic detection before prompt-based attacks scale further.

(CoinDesk has reached out to Coinbase for comments on the attack vector.)

]]>
https://earlybirdsinvest.com/coinbases-go-to-ai-coding-tool-found-vulnerable-to-copypasta-exploit/feed/ 0 57008
Amazon’s Lens Live Turns Camera Into a Shopping Tool https://earlybirdsinvest.com/amazons-lens-live-turns-camera-into-a-shopping-tool/ https://earlybirdsinvest.com/amazons-lens-live-turns-camera-into-a-shopping-tool/#respond Wed, 03 Sep 2025 20:37:16 +0000 https://earlybirdsinvest.com/amazons-lens-live-turns-camera-into-a-shopping-tool/

Amazon has introduced a new feature that blends visual search with artificial intelligence (AI), called Lens Live.

This AI tool allows shoppers to instantly search for products by pointing their phone camera at real-world objects.

This new tool builds on Amazon’s existing image-based search option, Amazon Lens, which already lets people look for products by uploading pictures or scanning barcodes.

What is a Cryptocurrency: For Beginners (Animated Explainer)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The feature is designed to support how people shop today, often browsing items in physical stores and then checking online to compare prices.

Amazon’s AI assistant, Rufus, is also built into the experience. Rufus offers short product overviews and suggests follow-up questions users can ask to learn more about what they are seeing.

This gives shoppers quick access to extra product details without needing to leave the camera view or dig through multiple pages.

On the technical side, Lens Live is powered by Amazon’s cloud services. It uses SageMaker for machine learning and OpenSearch for fast product lookup. These systems work behind the scenes to ensure matches are accurate and the experience is responsive.

At launch, Lens Live is only available on iOS devices and is currently limited to users in the US. Amazon has not confirmed a timeline for introducing the feature to Android or for users outside the US.

On August 26, Google introduced a new image-focused model called Gemini 2.5 Flash Image. What does it offer? Read the full story.


]]>
https://earlybirdsinvest.com/amazons-lens-live-turns-camera-into-a-shopping-tool/feed/ 0 56608
Ukraine Tests AI Tool 'Diia' to Simplify Access to Public Services https://earlybirdsinvest.com/ukraine-tests-ai-tool-diia-to-simplify-access-to-public-services/ https://earlybirdsinvest.com/ukraine-tests-ai-tool-diia-to-simplify-access-to-public-services/#respond Tue, 02 Sep 2025 00:59:50 +0000 https://earlybirdsinvest.com/ukraine-tests-ai-tool-diia-to-simplify-access-to-public-services/

Ukraine has rolled out a new artificial intelligence (AI) support tool on its government platform, Diia, according to a report by local news media UNITED24 Media.

This assistant is designed to simplify access to public services by helping users find the right options, answering their questions, and providing access to personal information stored in the system.

It is currently available for testing, and anyone with a Diia account can try it by asking a question through the platform’s homepage.

Layer 2 Scaling Solutions Explained With Animations

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The feature was introduced by Mykhailo Fedorov, Ukraine’s Minister of Digital Transformation, through a Telegram announcement on September 1. He noted the tool is to improve digital government and expand how people interact with public services online.

Diia’s main function is to guide people through service options and offer suggestions based on their situation.

For example, it can display someone’s insurance history or help them obtain official documents, such as a certificate of income, through a quick message. The process is simple: log in to Diia, use the search bar on the main page, and type a question. The assistant responds with steps or direct links to relevant services.

Fedorov also highlighted that the assistant’s capabilities will expand. One upcoming feature is voice interaction, which allows users to interact with the system verbally rather than typing.

Recently, China introduced a detailed plan to make AI a core part of everyday life and the economy. What did it say? Read the full story.


]]>
https://earlybirdsinvest.com/ukraine-tests-ai-tool-diia-to-simplify-access-to-public-services/feed/ 0 56297
Google Keep’s long-awaited sorting tool is finally starting to arrive https://earlybirdsinvest.com/google-keeps-long-awaited-sorting-tool-is-finally-starting-to-arrive/ https://earlybirdsinvest.com/google-keeps-long-awaited-sorting-tool-is-finally-starting-to-arrive/#respond Thu, 07 Aug 2025 16:56:15 +0000 https://earlybirdsinvest.com/google-keeps-long-awaited-sorting-tool-is-finally-starting-to-arrive/
google keep text formatting 1

Joe Maring / Android Authority

TL;DR

  • Google Keep is starting to roll out a new sort feature in its Android app.
  • You can now sort notes by custom order, date created, or date modified.
  • The update appears to be rolling out in version 5.25.302.02.90, but it may not be widely available just yet.

Google Keep is one of those apps that doesn’t change too often, but when it does, the updates are usually worth the wait. Now, Google appears to be rolling out a long-anticipated sorting feature to its Android app, giving some users a much easier way to organize their notes.

A user on X (@BlindMan199) first tipped us off that the new sort option had appeared, and we were able to verify that it’s available on at least one of our devices, though not all of them. That suggests it’s a limited rollout for now, but could expand more widely over the coming days or weeks.

If you have the feature, you’ll see a new sort icon inside the search bar at the top of the main screen, as shown in the screenshots above. Tapping this opens a pop-up menu at the bottom that gives you three different ways to sort your notes:

  • Custom: Lets you manually drag notes into any order;
  • Date created: Showing notes in the order you originally made them;
  • Date modified: Keeps the most recently edited ones at the top.

Keep has always allowed manual rearrangement and pinned notes, but outside of that, your list was stuck in reverse chronological order. For anyone juggling a large number of notes, these new options could make a big difference. The feature was spotted in development some time ago, but this is the first time it’s been available in the wild. It’s appearing in version 5.25.302.02.90 of the app.

Google hasn’t officially announced the rollout or whether it is tied to specific devices, accounts, or regions. If you don’t see the sort icon in Google Keep yet, you might just need to wait a little longer.

Thank you for being part of our community. Read our Comment Policy before posting.

]]>
https://earlybirdsinvest.com/google-keeps-long-awaited-sorting-tool-is-finally-starting-to-arrive/feed/ 0 51991
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/ https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/#respond Thu, 07 Aug 2025 00:53:11 +0000 https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/

Hacker staring at a box

Akira ransomware is abusing a legitimate Intel CPU tuning driver to turn off Microsoft Defender in attacks from security tools and EDRs running on target machines.

The abused driver is ‘rwdrv.sys’ (used by ThrottleStop), which the threat actors register as a service to gain kernel-level access.

This driver is likely used to load a second driver, ‘hlpdrv.sys,’ a malicious tool that manipulates Windows Defender to turn off its protections.

This is a ‘Bring Your Own Vulnerable Driver’ (BYOVD) attack, where threat actors use legitimate signed drivers that have known vulnerabilities or weaknesses that can be abused to achieve privilege escalation. This driver is then used to load a malicious tool that disables Microsoft Defender.

“The second driver, hlpdrv.sys, is similarly registered as a service. When executed, it modifies the DisableAntiSpyware settings of Windows Defender within \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware,” explain the researchers.

“The malware accomplishes this via execution of regedit.exe.”

This tactic was observed by Guidepoint Security, which reports seeing repeated abuse of the rwdrv.sys driver in Akira ransomware attacks since July 15, 2025.

“We are flagging this behavior because of its ubiquity in recent Akira ransomware IR cases. This high-fidelity indicator can be used for proactive detection and retroactive threat hunting,” continued the report.

To help defenders detect and block these attacks, Guidepoint Security has provided a YARA rule for hlpdrv.sys, as well as complete indicators of compromise (IoCs) for both drivers, their service names, and file paths where they are dropped.

Akira attacks on SonicWall SSLVPN

Akira ransomware was recently linked to attacks on SonicWall VPNs using what is believed to be an unknown flaw.

Guidepoint Security says it could neither confirm nor debunk the exploitation of a zero-day vulnerability in SonicWall VPNs by Akira ransomware operators.

In response to reports about elevated offensive activity, SonicWall advised disabling or restricting SSLVPN, enforcing multi-factor authentication (MFA), enabling Botnet/Geo-IP protection, and removing unused accounts.

Meanwhile, The DFIR Report has published an analysis of recent Akira ransomware attacks, highlighting the use of the Bumblebee malware loader delivered via trojanized MSI installers of IT software tools.

An example involves searches for “ManageEngine OpManager” on Bing, where SEO poisoning redirected the victim to the malicious site opmanager[.]pro.

Malicious website starting an Akira attack
Malicious website starting an Akira attack
Source: The DFIR Report

Bumblebee is launched via DLL sideloading, and once C2 communication is established, it drops AdaptixC2 for persistent access.

The attackers then conduct internal reconnaissance, create privileged accounts, and exfiltrate data using FileZilla, while maintaining access via RustDesk and SSH tunnels.

After approximately 44 hours, the main Akira ransomware payload (locker.exe) is deployed to encrypt systems across domains.

Until the SonicWall VPN situation clears up, system administrators should monitor for Akira-related activity and apply filters and blocks as indicators emerge from security research.

It is also strongly advised to only download software from official sites and mirrors, as impersonation sites have become a common source for malware.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/akira-ransomware-abuses-cpu-tuning-tool-to-disable-microsoft-defender/feed/ 0 51872
Hacker Slips Malicious Code Into Ethereum Dev Tool ETHcode https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/ https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/#respond Fri, 11 Jul 2025 17:06:14 +0000 https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/

Cybersecurity researchers at ReversingLabs recently found that a hacker injected harmful code into ETHcode, a toolset for Ethereum
ETH


$2,962.49

developers.

ETHcode is a VS Code extension that helps developers build and test Ethereum-compatible smart contracts and apps.

The suspicious code was added on June 17 by a GitHub user named Airez299, who had no earlier contributions to the project.

What is Staking Crypto? (Rewards & Risks Explained SIMPLY)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The update included 43 separate changes and about 4,000 edited lines, which mainly described a new testing system and additional features. Inside this large batch, two lines of malicious code were hidden.

The update was reviewed by GitHub’s automated AI tool and also checked by 7finney, the team that manages ETHcode. Neither spotted the problem, and only small edits were requested before approval.

According to ReversingLabs, the harmful code was disguised in a way that made it hard to notice. The first line was placed in a file with a name almost identical to an existing one and written in a scrambled style to make it harder to read.

The second line was designed to activate the first. When triggered, it launched a PowerShell script that downloaded and ran a batch file from a public file-sharing site.

ReversingLabs noted that it was likely designed to steal cryptocurrency stored on the victim’s computer or interfere with Ethereum projects being developed using the tool.

Recently, Sentinel Labs discovered a hacking campaign linked to groups in North Korea that uses malware called NimDoor. How does the malware work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/feed/ 0 47061
Leaks hint at Operator-like tool in ChatGPT ahead of GPT-5 launch https://earlybirdsinvest.com/leaks-hint-at-operator-like-tool-in-chatgpt-ahead-of-gpt-5-launch/ https://earlybirdsinvest.com/leaks-hint-at-operator-like-tool-in-chatgpt-ahead-of-gpt-5-launch/#respond Fri, 04 Jul 2025 01:46:42 +0000 https://earlybirdsinvest.com/leaks-hint-at-operator-like-tool-in-chatgpt-ahead-of-gpt-5-launch/

GPT

A few new code references in the ChatGPT web app and Android point to an Operator-like tool in GPT’s chain of thoughts.

As spotted by Tibor on X, the Android beta has strings like “click,” “drag,” “type,” and even “terminal feed,” which seem to suggest that ChatGPT could soon call a remote browser or sandboxed environment (Operator?).

For those unaware, OpenAI already has Operator, which uses an AI agent to navigate a remote browser session and execute tasks for you.

These references suggest that ChatGPT’s thinking model might call a browser or APIs to execute tasks. There are also references to “Checking available APIs” and “Reading API documentation.”

GPT
Android beta include mentions of “computer tool” actions (click, performing computer actions, etc.)

It’s also worth noting that the code mentions an “intake form,” so OpenAI may gate this feature behind an invite-only beta before rolling it out more widely.

Could it be ChatGPT-5 or some other model? We don’t know, and we likely won’t anytime soon as OpenAI is busy with its standoff with Meta.

Tines Needle

While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

]]>
https://earlybirdsinvest.com/leaks-hint-at-operator-like-tool-in-chatgpt-ahead-of-gpt-5-launch/feed/ 0 45632
You could streamline your workday with this tool that bundles ChatGPT, Midjourney, and more https://earlybirdsinvest.com/you-could-streamline-your-workday-with-this-tool-that-bundles-chatgpt-midjourney-and-more/ https://earlybirdsinvest.com/you-could-streamline-your-workday-with-this-tool-that-bundles-chatgpt-midjourney-and-more/#respond Fri, 06 Jun 2025 08:55:27 +0000 https://earlybirdsinvest.com/you-could-streamline-your-workday-with-this-tool-that-bundles-chatgpt-midjourney-and-more/

]]>
https://earlybirdsinvest.com/you-could-streamline-your-workday-with-this-tool-that-bundles-chatgpt-midjourney-and-more/feed/ 0 40436
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender https://earlybirdsinvest.com/new-defendnot-tool-tricks-windows-into-disabling-microsoft-defender/ https://earlybirdsinvest.com/new-defendnot-tool-tricks-windows-into-disabling-microsoft-defender/#respond Sun, 18 May 2025 05:32:24 +0000 https://earlybirdsinvest.com/new-defendnot-tool-tricks-windows-into-disabling-microsoft-defender/

Microsoft Defender

A new tool called ‘Defendnot’ can disable Microsoft Defender on Windows devices by registering a fake antivirus product, even when no real AV is installed.

The trick utilizes an undocumented Windows Security Center (WSC) API that antivirus software uses to tell Windows it is installed and is now managing the real-time protection for the device.

When an antivirus program is registered, Windows automatically disables Microsoft Defender to avoid conflicts from running multiple security applications on the same device.

The Defendnot tool, created by researcher es3n1n, abuses this API by registering a fake antivirus product that meets all of Windows’ validation checks.

The tool is based on a previous project called no-defender, which used code from a third-party antivirus product to spoof registration with WSC. That earlier tool was pulled from GitHub after the vendor filed a DMCA takedown.

“Then, after a few weeks after the release, the project blew up quite a bit and gained ~1.5k stars, after that the developers of the antivirus I was using filed a DMCA takedown request and I didn’t really want to do anything with that so just erased everything and called it a day,” the developer explains in a blog post.

Defendnot avoids copyright issues by building the functionality from scratch through a dummy antivirus DLL.

Normally, WSC API is safeguarded through Protected Process Light (PPL), valid digital signatures, and other features.

To bypass these requirements, Defendnot injects its DLL into a system process, Taskmgr.exe, that is signed and already trusted by Microsoft. From within that process, it can register the dummy antivirus with a spoofed display name.

Once registered, Microsoft Defender immediately shuts itself off, leaving no active protection on the device.

Defendnot registered on a device
Defendnot registered on a device
Source: BleepingComputer

The tool also includes a loader that passes configuration data via a ctx.bin file and lets you set the antivirus name you want to use, turn off registration, and enable verbose logging.

For persistence, Defendnot creates an autorun through the Windows Task Scheduler so that it starts when you log in to Windows.

While Defendnot is considered a research project, the tool demonstrates how trusted system features can be manipulated to turn off security features.

Microsoft Defender is currently detecting and quarantining Defendnot as a ‘Win32/Sabsik.FL.!ml; detection.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/new-defendnot-tool-tricks-windows-into-disabling-microsoft-defender/feed/ 0 36869
WordPress plugin disguised as a security tool injects backdoor https://earlybirdsinvest.com/wordpress-plugin-disguised-as-a-security-tool-injects-backdoor/ https://earlybirdsinvest.com/wordpress-plugin-disguised-as-a-security-tool-injects-backdoor/#respond Wed, 30 Apr 2025 23:31:19 +0000 https://earlybirdsinvest.com/wordpress-plugin-disguised-as-a-security-tool-injects-backdoor/

Wordpress

A new malware campaign targeting WordPress sites employs a malicious plugin disguised as a security tool to trick users into installing and trusting it.

According to Wordfence researchers, the malware provides attackers with persistent access, remote code execution, and JavaScript injection. At the same time, it remains hidden from the plugin dashboard to evade detection.

Wordfence first discovered the malware during a site cleanup in late January 2025, where it found a modified ‘wp-cron.php’ file, which creates and programmatically activates a malicious plugin named ‘WP-antymalwary-bot.php.’

Other plugin names used in the campaign include:

  • addons.php
  • wpconsole.php
  • wp-performance-booster.php
  • scr.php

If the plugin is deleted, wp-cron.php re-creates and reactivates it automatically on the next site visit.

Lacking server logs to help identify the exact infection chain, Wordfence hypothesizes the infection occurs via a compromised hosting account or FTP credentials.

Not much is known about the perpetrators, though the researchers noted that the command and control (C2) server is located in Cyprus, and there are traits similar to a June 2024 supply chain attack.

Once active on the server, the plugin performs a self-status check and then gives the attacker administrator access.

“The plugin provides immediate administrator access to threat actors via the emergency_login_all_admins function,” explains Wordfence in its writeup.

“This function utilizes the emergency_login GET parameter in order to allow attackers to obtain administrator access to the dashboard.”

“If the correct cleartext password is provided, the function fetches all administrator user records from the database, picks the first one, and logs the attacker in as that user.”

Next, the plugin registers an unauthenticated custom REST API route that allows the insertion of arbitrary PHP code into all active theme header.php files, clearing of plugin caches, and other commands processed via a POST parameter.

An updated version of the malware can also inject base64-decoded JavaScript into the site’s

section, likely for serving visitors ads, spam, or redirecting them to unsafe sites.

Apart from file-based indicators like the listed plugins, website owners should scrutinize their ‘wp-cron.php’ and ‘header.php’ files for unexpected additions or modifications.

Access logs containing ’emergency_login,’ ‘check_plugin,’ ‘urlchange,’ and ‘key’ should also serve as red flags, warranting further investigation.

]]>
https://earlybirdsinvest.com/wordpress-plugin-disguised-as-a-security-tool-injects-backdoor/feed/ 0 33692