Vulnerability – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 19 Jul 2025 01:38:54 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Vulnerability – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hacker reconnaissance work continues on TeleMessage app vulnerability — Report https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/ https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/#respond Sat, 19 Jul 2025 01:38:53 +0000 https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/

Hackers are continuing to seek out opportunities to exploit the infamous CVE-2025-48927 vulnerability involved in TeleMessage, according to a new report from threat intelligence company GreyNoise.

GreyNoise’s tag, which monitors attempts to take advantage of the vulnerability, has detected 11 IP addresses that have attempted the exploit since April.

Other IP addresses may be performing reconnaissance work: A total of 2,009 IPs have searched for Spring Boot Actuator endpoints in the past 90 days, and 1,582 IPs have specifically targeted the /health endpoints, which commonly detect Spring Boot Actuator deployments.

The flaw allows hackers to extract data from vulnerable systems. The issue “stems from the platform’s continued use of a legacy confirmation in Spring Boot Actuator, where a diagnostic /heapdump endpoint is publicly accessible without authentication,” the research team told Cointelegraph.

TeleMessage is similar to the Signal App but allows for the archiving of chats for compliance purposes. Based in Israel, the company was acquired by US company Smarsh in 2024, before temporarily suspending services after a security breach in May that resulted in files being stolen from the app.

“TeleMessage has stated that the vulnerability has been patched on their end,” said Howdy Fisher, a member of the GreyNoise team. “However, patch timelines can vary depending on a variety of factors.”

Although security weaknesses in apps are more common than desired, the TeleMessage vulnerability could be significant for its users: government organizations and enterprises. Users of the app may include former US government officials like Mike Waltz, US Customs and Border Protection and crypto exchange Coinbase.

GreyNoise recommends users block malicious IPs and disable or restrict access to the /heapdump endpoint. In addition, limiting exposure to Actuator endpoints may be helpful, it said.

Related: Threat actors using ‘elaborate social engineering scheme’ to target crypto users — Report

Crypto theft rising in 2025; credentials on darknet go for thousands

Chainalysis’ latest crime report notes that over $2.17 billion has been stolen so far in 2025, a pace would take crypto-related thefts to new highs. Notable security attacks over the past months include physical “wrench attacks” on Bitcoin holders and high-profile incidents such as the February hack of crypto exchange Bybit.

Attempts to steal credentials often involve phishing attacks, malicious malware, and social engineering. 

Magazine: Coinbase hack shows the law probably won’t protect you — Here’s why

]]>
https://earlybirdsinvest.com/hacker-reconnaissance-work-continues-on-telemessage-app-vulnerability-report/feed/ 0 48436
UK launches vulnerability research program for external experts https://earlybirdsinvest.com/uk-launches-vulnerability-research-program-for-external-experts/ https://earlybirdsinvest.com/uk-launches-vulnerability-research-program-for-external-experts/#respond Tue, 15 Jul 2025 05:54:15 +0000 https://earlybirdsinvest.com/uk-launches-vulnerability-research-program-for-external-experts/

UK launches vulnerability research program for external experts

UK’s National Cyber Security Centre (NCSC) has announced a new Vulnerability Research Initiative (VRI) that aims to strengthen relations with external cybersecurity experts.

The agency already conducts internal vulnerability research on a wide range of technologies and will continue to do so. However, the launch of VRI will create a parallel program designed to improve discovery and sharing of critical insights with the community more expeditiously.

The NCSC is the UK’s cybersecurity authority, tasked to protect from cyber threats targeting the country’s critical infrastructure, government, businesses, and citizens.

To fulfill this mission, the agency publishes alerts, cybersecurity guidance, and threat analysis, provides support in incident response, and coordinates related activities with public, private, and international partners.

The VRI is a structured collaboration between the NCSC and external cybersecurity researchers to improve the UK’s capabilities in identifying and understanding software and hardware vulnerabilities.

“The Vulnerability Research Initiative (VRI) is NCSC’s programme of research with external partners on VR,” reads the agency’s announcement.

“The VRI’s mission is to strengthen the UK’s ability to carry out VR. We work with the best external vulnerability researchers to deliver a deep understanding of security on a wide range of technologies we care about.​”

NCSC will partner with skilled external vulnerability researchers who will be given objectives to identify flaws in specific products of interest, assess proposed mitigations, and finally disclose the flaws through the ‘Equities Process’ procedure.

The researchers will also submit to the NCSC details about the tools they used and the methodologies they followed during their VR activities, to help develop a framework of effective practices.

NCSC states that it plans to involve more experts in emerging specialized areas such as AI-powered vulnerability discovery.

Interested security specialists are invited to email at vri@ncsc.gov.uk with their skills and focus areas.

The email address address should not be used for sending full vulnerability reports, the agency notes. NCSC recommends using this portal to report a vulnerability instead.

Tines Needle

While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

]]>
https://earlybirdsinvest.com/uk-launches-vulnerability-research-program-for-external-experts/feed/ 0 47722
Secured #2: Public Vulnerability Disclosures https://earlybirdsinvest.com/secured-2-public-vulnerability-disclosures/ https://earlybirdsinvest.com/secured-2-public-vulnerability-disclosures/#respond Sat, 17 May 2025 18:56:48 +0000 https://earlybirdsinvest.com/secured-2-public-vulnerability-disclosures/

Today, we disclosed the first set of vulnerabilities from the Ethereum Foundation’s Bug Bounty Programs. These vulnerabilities were previously discovered and reported directly to the Ethereum Foundation or client teams via the Bug Bounty Programs for both the Execution Layer and Consensus Layer.

Through its Bug Bounty Programs, which allow the Ethereum Foundation (EF) to coordinate and cross-check vulnerabilities across clients, the EF currently accepts vulnerability reports for Nimbus, Teku, Lighthouse, Prysm, Lodestar, Go Ethereum, Nethermind, Erigon and Besu.

New repository & vulnerability list

The full list of vulnerabilities, along with additional information, can be found in a git repository here.

The new disclosures repository catalogues all known vulnerabilities that were patched prior to the latest hardforks on the Execution Layer and Consensus Layer.

We would like to give a massive shout out to everyone involved in the discovery and reporting of vulnerabilities, as well as to the teams responsible for fixing them. While we have attempted to include the names or aliases of the reporters, there are many developers and researchers within the client teams and in the Ethereum Foundation who found and corrected vulnerabilities outside of the bounty program. There are also many unsung heroes such as client team developers, community members, and many more who have spent countless hours triaging, cross-checking, and mitigating vulnerabilities before they could be exploited.

For more information, and to learn more about disclosure policies, timelines, and cataloging, head over to the new disclosures repository.

Your immense efforts have been instrumental to ensuring Ethereum’s security. Thank you!

]]>
https://earlybirdsinvest.com/secured-2-public-vulnerability-disclosures/feed/ 0 36782
European Union public vulnerability database enters beta phase https://earlybirdsinvest.com/european-union-public-vulnerability-database-enters-beta-phase/ https://earlybirdsinvest.com/european-union-public-vulnerability-database-enters-beta-phase/#respond Wed, 14 May 2025 20:47:43 +0000 https://earlybirdsinvest.com/european-union-public-vulnerability-database-enters-beta-phase/

Forward-looking: In today’s world and age, having a centralized resource for collecting and sharing information about security vulnerabilities is essential. The US administration recently signaled it doesn’t have this kind of priorities anymore, so the European Union is preparing a potential alternative for keeping the technology world safe and informed.

The European Commission has launched a new vulnerability database managed by the EU Agency for Cybersecurity (ENISA). The beta version of the European Vulnerability Database (EUVD) is already live, promising a more effective approach to cybersecurity and critical information sharing for professionals and organizations across the continent.

The EUVD meets the vulnerability management requirements of the NIS2 Directive, a 2023 framework adopted by the European Parliament to improve cybersecurity in critical sectors like energy, transport, and healthcare. It also helps implement the Cyber Resilience Act, which requires stronger protections for products with digital components.

European officials have described the initiative as a move to strengthen the EU’s technological sovereignty. Henna Virkkunen, the European Commission’s executive vice president for Tech Sovereignty, Security, and Democracy, welcomed the EUVD as a key step toward Europe’s digital security and resiliency.

“By bringing together vulnerability information relevant to the EU market, we are raising cybersecurity standards, enabling public and private stakeholders to better protect our shared digital spaces with greater efficiency and autonomy,” Virkkunen said.

The ENISA says this data consolidation will make it easier for organizations to identify and respond to vulnerabilities, fostering a more proactive cybersecurity environment across the continent. By centralizing and streamlining the information, the EUVD aims to reduce the time it takes to address critical security issues, ultimately enhancing the region’s digital resilience.

The EUVD features three dashboards highlighting critical vulnerabilities, exploited bugs, and “EU-coordinated” flaws. The latter includes issues managed by European CSIRTs. Most data comes from open-source databases, while national CSIRTs provide additional details through advisories and alerts.

Starting September 2026, the EU will require hardware and software manufacturers to report actively exploited vulnerabilities. While Brussels authorities mention the CVE database only tangentially, the EUVD is a practical response to the Trump administration’s attempts to defund critical bug tracking. Should future efforts to slash funding for cyber initiatives succeed, data from the CVE system could seamlessly migrate to the EUVD.

]]>
https://earlybirdsinvest.com/european-union-public-vulnerability-database-enters-beta-phase/feed/ 0 36235
Secured #5: Public Vulnerability Disclosures Update https://earlybirdsinvest.com/secured-5-public-vulnerability-disclosures-update/ https://earlybirdsinvest.com/secured-5-public-vulnerability-disclosures-update/#respond Mon, 31 Mar 2025 12:09:01 +0000 https://earlybirdsinvest.com/secured-5-public-vulnerability-disclosures-update/

Today, we have disclosed the second set of vulnerabilities from the Ethereum Foundation Bug Bounty Program! 🥳 These vulnerabilities were previously discovered and reported directly to the Ethereum Foundation.

When bugs are reported and validated, the Ethereum Foundation coordinates disclosures to affected teams and helps cross-check vulnerabilities across all clients. The Bug Bounty Program currently accepts reports for the following client software:

  • Erigon
  • Go Ethereum
  • Lodestar
  • Nethermind
  • Lighthouse
  • Prysm
  • Teku
  • Besu
  • Nimbus

In addition to client software, the Bug Bounty Program also covers the Deposit Contract, Execution Layer & Consensus Layer Specifications and Solidity. 🙏

Repository & vulnerability list

Since the last vulnerability disclosure has been quite eventful with events such as the Merge 🐼 and the max bounty reward increase to $250,000. 💰

The highest paid reward during this period was $50,000. This was awarded to scio for reporting an issue in which Lighthouse beacon nodes crashed via malicious BlocksByRange messages containing an overly large count value. You can read more about this specific vulnerability here. 💥

Another notable set of vulnerabilites has been around fork choice attacks. EF researchers and client teams investigated and patched attacks that were able to cause long reorgs. 👀

Guido Vranken holds the top spot most positive reports in this period. At the same time, Guido managed to collect the most points for the Bug Bounty Leaderboard! 🏆

We also have two bounty hunters who decided to donate their rewards to charities: nrv and PwningEth! 🔥

The full list of new vulnerabilities, along with full details, can be found in the disclosures repository.

All vulnerabilities added to the disclosures catalogue were patched prior to the latest hardforks on the Execution Layer and Consensus Layer.

For more information, and to learn more about disclosure policies, timelines, and cataloging, head over to the disclosures repository.

Thank you 🙏

We would like to give a massive shout out to everyone involved in the discovery and reporting of vulnerabilities, as well as to the teams responsible for fixing them. While we have attempted to include the names or aliases of all reporters, there are many developers and researchers within the client teams and in the Ethereum Foundation who found and corrected vulnerabilities outside of the bounty program. There are also many unsung heroes such as client team developers, community members, and many more who have spent countless hours triaging, cross-checking, and mitigating vulnerabilities before they could be exploited.

Your immense efforts have been instrumental to ensuring Ethereum’s security. Thank you!

]]>
https://earlybirdsinvest.com/secured-5-public-vulnerability-disclosures-update/feed/ 0 28216