Des cartes du Steam Workshop pour Meccha Chameleon infectées par un logiciel malveillant

Un logiciel malveillant a été diffusé via plusieurs cartes sur le Steam Workshop pour Meccha Chameleon. Un chercheur indépendant a identifié le problème le 24 juillet. Les développeurs ont publié un correctif le lendemain, tandis que le serveur Discord officiel du jeu était piraté.

Un chercheur indépendant nommé Feint a publié un rapport sur Medium décrivant comment la carte Laser Tag Neon ouvrait une fenêtre d'invite de commande et téléchargeait un script pour installer un logiciel malveillant.

La carte a été supprimée après le rapport, mais de nouvelles cartes malveillantes sont apparues par la suite. Les développeurs lemorion_1224 ont déclaré que la version 3.1.0 du jeu corrigeait la vulnérabilité.

Le serveur Discord officiel a été compromis le 25 juillet. Le PC d'un ingénieur système a été infecté lors de l'enquête sur le logiciel malveillant et un pirate a contourné l'authentification à deux facteurs pour modifier les autorisations et bannir des membres du personnel.

Le jeu lui-même reste intact. Les développeurs ont contacté le support Discord et ont indiqué qu'ils créeraient un nouveau serveur si l'original ne pouvait pas être récupéré.

Articles connexes

Illustration of a hacker exploiting Meta's AI chatbot to hijack Instagram accounts by changing email addresses and bypassing security.
Image générée par IA

Meta patches ai chatbot flaw used to hijack instagram accounts

Rapporté par l'IA Image générée par IA

Hackers exploited Meta's AI support chatbot to take over Instagram accounts by tricking it into changing associated email addresses. The vulnerability allowed password resets without two-factor authentication after matching locations via VPN. Meta resolved the issue with an emergency patch on May 29.

Meccha Chameleon, a new online multiplayer game, reached over 300000 concurrent players on Steam during a recent afternoon.

Rapporté par l'IA

Meccha Chameleon, a Prop Hunt-style game on Steam, has gained massive popularity through creative player strategies. The title from developer lemorion_1224 allows users to paint characters for camouflage in multiplayer matches.

Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.

Rapporté par l'IA

Cybersecurity researchers have identified a fraudulent website mimicking the popular AI tool Claude that delivers backdoor malware to visitors. The discovery highlights how cybercriminals are capitalizing on growing interest in artificial intelligence platforms.

Ce site utilise des cookies

Nous utilisons des cookies pour l'analyse afin d'améliorer notre site. Lisez notre politique de confidentialité pour plus d'informations.
Refuser