✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Computer Games
Breach intelligence, attack campaigns, and threat reports targeting the Computer Games sector.
Explore Other Sectors
Computer Games Threat Reports
Rockstar Games' 2026 Data Breach: A Wake-Up Call for Third-Party Security
In April 2026, Rockstar Games experienced a data breach orchestrated by the hacker group ShinyHunters. The attackers exploited a vulnerability in Anodot, a third-party analytics platform integrated with Rockstar's Snowflake cloud infrastructure, to steal authentication tokens. This allowed unauthorized access to Rockstar's internal data, leading to a ransom demand with a deadline of April 14, 2026. Rockstar confirmed that only a limited amount of non-material company information was accessed, emphasizing no impact on their operations or players. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/rockstar-games-confirms-it-was-hacked-by-malicious-group-shinyhunters-takes-credit-gives-until-april-14-to-pay-ransom-or-risk-leaking-confidential-data-shinyhunters?utm_source=openai)) This incident underscores the growing trend of cyberattacks targeting third-party service integrations, highlighting the critical need for organizations to assess and secure their entire supply chain. The breach also serves as a reminder of the persistent threats posed by groups like ShinyHunters, known for exploiting indirect access points to infiltrate major corporations. ([techspot.com](https://www.techspot.com/news/112038-rockstar-games-hit-ransom-demand-after-third-party.html?utm_source=openai))
3 months ago
Kill Chain
GPUBreach: Unveiling the 2026 NVIDIA GDDR6 RowHammer Vulnerability
In April 2026, researchers from the University of Toronto unveiled 'GPUBreach,' a sophisticated RowHammer attack targeting NVIDIA GPUs equipped with GDDR6 memory. This attack exploits bit-flips in GPU memory to corrupt page tables, granting an unprivileged process arbitrary read/write access to GPU memory. By leveraging vulnerabilities in the NVIDIA driver, attackers can escalate privileges to gain full control over the host system, even with IOMMU protections enabled. The implications are severe, particularly for cloud AI infrastructures and multi-tenant GPU deployments, as GPUBreach enables attackers to compromise entire systems without physical access. This development underscores the evolving nature of hardware-based attacks and the necessity for robust security measures in GPU environments. ([thehackernews.com](https://thehackernews.com/2026/04/new-gpubreach-attack-enables-full-cpu.html?utm_source=openai))
3 months ago
Kill Chain
REF1695's 2023 Campaign: Unveiling the Threat of Fake Installers
In November 2023, a financially motivated threat actor, codenamed REF1695, initiated a campaign leveraging fake software installers to deploy remote access trojans (RATs) and cryptocurrency miners. The attackers utilized ISO files containing a .NET Reactor-protected loader and instructions guiding users to bypass Microsoft Defender SmartScreen protections. This method facilitated the installation of a previously undocumented .NET implant known as CNB Bot, enabling unauthorized access and resource exploitation on compromised systems. Beyond cryptomining, REF1695 monetized infections through Cost Per Action (CPA) fraud, directing victims to content locker pages under the guise of software registration. This multifaceted approach not only compromised system integrity but also led to financial losses for affected organizations. The incident underscores the evolving tactics of cybercriminals who combine traditional malware deployment with social engineering techniques to maximize their illicit gains. Organizations are urged to enhance their cybersecurity measures, including user education on recognizing phishing attempts and the importance of verifying software sources, to mitigate such threats.
3 months ago
Kill Chain
Critical Security Alert: CVE-2026-5281 in Google Chrome's Dawn Component
In April 2026, a critical use-after-free vulnerability, identified as CVE-2026-5281, was discovered in Google Chrome's Dawn component, which handles WebGPU operations. This flaw allows remote attackers who have compromised the renderer process to execute arbitrary code via crafted HTML pages. The vulnerability affects Chrome versions prior to 146.0.7680.178. Google has released a patch to address this issue, and users are strongly advised to update their browsers immediately to mitigate potential risks. ([leakycreds.com](https://www.leakycreds.com/vulnerability/CVE-2026-5281?utm_source=openai)) The inclusion of CVE-2026-5281 in CISA's Known Exploited Vulnerabilities catalog underscores the severity of the threat, as it has been actively exploited in the wild. This incident highlights the ongoing challenges in securing widely used software components and the importance of timely updates to protect against emerging threats. ([thecyberthrone.in](https://thecyberthrone.in/2026/04/02/cve-2026-5281-google-chrome-dawn-use-after-free-under-active-exploitation/?utm_source=openai))
3 months ago
Kill Chain
Critical Supply Chain Attack: Axios npm Package Compromised in March 2026
In late March 2026, attackers compromised the npm account of a lead maintainer of Axios, a widely used JavaScript HTTP client library, and published two malicious versions: axios@1.14.1 and axios@0.30.4. These versions included a hidden dependency, plain-crypto-js@4.2.1, which executed a cross-platform Remote Access Trojan (RAT) upon installation, targeting macOS, Windows, and Linux systems. The malicious packages were live for approximately two to three hours before being removed, but during that time, any system that installed these versions was potentially compromised. ([csoonline.com](https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks, where trusted software components are manipulated to distribute malware. Given Axios's extensive use, with over 100 million weekly downloads, the potential impact was significant, highlighting the need for robust security measures in software development and distribution processes. ([csoonline.com](https://www.csoonline.com/article/4152696/attackers-trojanize-axios-http-library-in-highest-impact-npm-supply-chain-attack.html?utm_source=openai))
3 months ago
Kill Chain
GitHub OpenClaw Deployer Repo Delivers Trojan
In early March 2026, a sophisticated supply chain attack targeted the OpenClaw AI agent ecosystem. Threat actors uploaded over 300 malicious 'skills' to ClawHub, OpenClaw's official plugin marketplace, disguising them as legitimate productivity tools. Once installed, these skills deployed the Atomic macOS Stealer (AMOS) on macOS systems and GhostSocks proxy malware on Windows systems, enabling unauthorized data exfiltration and system control. The campaign remained undetected for several weeks, compromising an unknown number of users. This incident underscores the escalating risks associated with AI agent ecosystems and the exploitation of trusted platforms like GitHub and ClawHub. The attackers' ability to manipulate trust signals and evade automated security measures highlights the need for enhanced vigilance and robust security protocols in open-source AI environments.
4 months ago
Kill Chain
Unveiling the 'Bliss' Exploit: How the Xbox One Was Hacked in 2026
In March 2026, security researcher Markus 'Doom' Gaasedelen unveiled a hardware-based exploit named 'Bliss' that successfully compromised Microsoft's Xbox One console, which had been considered 'unhackable' since its 2013 release. Utilizing a technique called Voltage Glitch Hacking (VGH), Gaasedelen applied two precise voltage disturbances to the CPU's voltage rails during the boot process. These glitches bypassed the memory protection setup and exploited a memcpy operation, allowing the execution of attacker-controlled code. This method grants complete system control, enabling the loading of unsigned code at all levels, including the Hypervisor and OS, and is deemed unpatchable as it targets the boot ROM embedded in hardware. The 'Bliss' exploit has significant implications for digital archivists and the development of emulation and modding tools for the Xbox One platform. ([tomshardware.com](https://www.tomshardware.com/video-games/console-gaming/microsofts-unhackable-xbox-one-has-been-hacked-by-bliss-the-2013-console-finally-fell-to-voltage-glitching-allowing-the-loading-of-unsigned-code-at-every-level?utm_source=openai))
4 months ago
Kill Chain
Steam Malware Incident 2025: A Wake-Up Call for Digital Platform Security
Between July and September 2025, multiple games on the Steam platform, including 'BlockBlasters' and 'PirateFi,' were found to contain malware designed to steal users' cryptocurrency and personal data. These games, initially appearing legitimate, were later updated to include malicious code that compromised the security of players' systems. The malware led to significant financial losses, with reports indicating over $150,000 stolen from affected users. Notably, Twitch streamer Raivo 'RastalandTV' Plavnieks lost $32,000 in donations intended for his cancer treatment after installing 'BlockBlasters.' Valve Corporation, the operator of Steam, removed the malicious games from the platform and advised affected users to perform full system resets to eliminate potential threats. This incident underscores the evolving tactics of cybercriminals targeting digital platforms and the importance of vigilant security practices for both platform operators and users.
4 months ago
Kill Chain
Cloud Imperium Games Data Breach: A Wake-Up Call for the Gaming Industry
In January 2026, Cloud Imperium Games (CIG), the developer behind 'Star Citizen,' experienced a sophisticated cyberattack resulting in unauthorized access to backup systems containing user data. The breach, discovered on January 21, exposed personal information including names, contact details, usernames, and dates of birth. Notably, financial information and passwords remained secure. CIG addressed the intrusion promptly, implementing enhanced security measures to prevent further incidents. ([theregister.com](https://www.theregister.com/2026/03/03/brit_games_studio_cloud_imperium/?utm_source=openai)) This incident underscores the critical importance of timely breach disclosure and robust data protection practices in the gaming industry. The delayed notification has raised concerns about transparency and user trust, highlighting the need for companies to adhere to regulatory requirements and maintain open communication with their user base. ([scworld.com](https://www.scworld.com/brief/cloud-imperium-faces-backlash-over-delayed-data-breach-disclosure?utm_source=openai))
4 months ago
Kill Chain
Trojanized Gaming Tools Deploy Java-Based RAT via Browsers and Chat Platforms
In February 2026, threat actors distributed trojanized gaming utilities via browsers and chat platforms, deploying a Java-based Remote Access Trojan (RAT). The attack utilized a malicious downloader to stage a portable Java runtime and execute a JAR file named jd-gui.jar, employing PowerShell and living-off-the-land binaries like cmstp.exe for stealthy execution. The malware established persistence through scheduled tasks and startup scripts, connecting to an external server for command-and-control communications, enabling data exfiltration and deployment of additional payloads. ([thehackernews.com](https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals, highlighting the increasing use of legitimate tools for malicious purposes and the targeting of gaming communities. Organizations must remain vigilant against such sophisticated attack vectors to protect sensitive data and maintain operational integrity.
5 months ago
Kill Chain
Unveiling the Wormable XMRig Campaign: A Deep Dive into BYOVD Exploits and Time-Based Logic Bombs
In February 2026, cybersecurity researchers uncovered a sophisticated cryptojacking campaign that utilized pirated software bundles to deploy a customized XMRig miner on compromised systems. The malware exhibited worm-like capabilities, spreading via external storage devices, and employed a 'Bring Your Own Vulnerable Driver' (BYOVD) technique to escalate privileges. Additionally, it incorporated a time-based logic bomb set to deactivate the malware after December 23, 2025, indicating a planned operational timeframe. This campaign underscores the evolving tactics of cybercriminals, combining social engineering, legitimate software exploitation, and advanced persistence mechanisms to maximize cryptocurrency mining output. The use of BYOVD exploits and logic bombs highlights the need for robust security measures to detect and mitigate such multifaceted threats.
5 months ago
Kill Chain
NationStates Data Breach Exposes User Information
In late January 2026, NationStates, a popular multiplayer browser-based game, experienced a significant data breach. A long-standing community member, previously recognized for responsible vulnerability disclosures, identified a critical flaw in the game's 'Dispatch Search' feature. While testing this vulnerability, the individual exceeded authorized boundaries, achieving remote code execution on the production server. This unauthorized access led to the copying of sensitive user data, including email addresses, MD5-hashed passwords, IP addresses, and browser UserAgent strings. The breach was publicly disclosed on January 30, 2026, prompting a temporary shutdown of the site for investigation and remediation. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/nationstates-confirms-data-breach-shuts-down-game-site/?utm_source=openai)) This incident underscores the risks associated with inadequate input sanitization and the use of outdated cryptographic practices, such as MD5 for password hashing. It highlights the necessity for organizations to implement robust security measures, including regular code audits, modern encryption standards, and strict access controls, to prevent similar breaches.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports