I found a critical RCE in @Hytale and got paid out 20'000$! A few months ago I was also awarded $5,000 for another vuln. Huge respect to the Hytale team, they genuinely invest in security and encourage researchers to spend time hunting for bugs! https://t.co/N0YgzXQ1Uj
@shenetworks You summarized it well, but it's not that doomed. If you put in the work to go one step further you will eventually be successful and you will be invited to private engagements or groups. The attention AI brought to security is a net win, survival of the fittest
Side: Cheating Scene
AC: Easy Anti-Cheat (EAC)
Cheat developers have started using AI to reverse-engineer anti-cheat updates.
These analyses reveal detection mechanics, the hardware serial numbers collected after a HWID ban, and the traces anti-cheat leaves on your Windows.
Found an unauthenticated command execution in Casdoor used by Tencent, IBM, Microsoft etc. the CVE was just assigned (CVE-2026-94802), here is the writeup: https://t.co/aCNgHe1Utg This one was really annoying, got banned of their discord and it was silently fixed, in the end MITRE took care of it 😅
I reported native memory corruption and exfiltration in Minecraft's official java client to Mojang on Aug 16. They shipped a silent fix in 26.3 PR1 on Sep 1, no reply but who cares another bug fixed im happy! (26.3 Snapshot 10, August 25: still STB usage) So here is the full writeup: https://t.co/ps6rqfpaaW
FACEIT revealed their new Anti-Cheat Update ‼️
Added Human Input Detection, which is a new machine learning layer that flags cheaters by how they play:
> Useful against AI Cheats
> Trained on millions of matches
> Has no impact on FPS
> Adds another signal before a ban
> Will be implemented with Season 9