🎮 Mobile Gaming Application with 40M+ Downloads Allegedly Targeted by Vulnerability Sale
A threat actor is advertising the sale of alleged vulnerabilities affecting a mobile strategy game described as having more than 40 million downloads.
* The post references the game "War and Order" and claims multiple security weaknesses were identified.
* According to the seller, the alleged vulnerabilities include:
* Account takeover capabilities
* Backend information disclosure
* Hot-update/code delivery weaknesses
* Client-side remote code execution (RCE) claims
* Ability to display messages across active user screens
* The threat actor states additional findings were documented but not publicly disclosed and claims proof-of-concept (PoC) material is available for buyers.
* The vulnerabilities are being offered for sale for approximately $1,200.
* No technical details, exploit code, or independent validation were provided in the visible portion of the listing.
* At the time of reporting, the authenticity of the claims, the severity of the alleged vulnerabilities, and whether the vendor has been notified remain unverified.
Analyst Note:
The underground sale of alleged gaming platform vulnerabilities can pose significant risks beyond the gaming ecosystem. If validated, account takeover and backend compromise capabilities could enable fraud, theft of virtual assets, abuse of payment systems, large-scale phishing campaigns, or disruption of game services affecting millions of users.
#DDW #Intelligence #DarkWeb #Gaming
FYI, new Cyanide repo link: https://t.co/Y2PbhBmELU
Old repo was a fork I couldn't detach. All releases migrated – update your AltSource if you're sideloading.
New writeup with PoCs! I used Codex to follow breadcrumbs from @calif_io’s Mythos-assisted Apple M5 memory-integrity bypass demo & see what I could recreate from the outside.
Didn’t rebuild the chain, but did find 2 new macOS kernel bugs along the way.
https://t.co/H9QJUCpgSf
Folks: when you write skills, ask your agent to be token efficient, relax grammer. I see too many skills that write books in the skill description, and all that crap is loaded into every context.
I wrote a skill that finds the worst offenders. https://t.co/kfaaJpxMXE
The Enswilde project has been discontinued. There will be no further updates in the future. However, you can look into Lara. It offers much better support. https://t.co/gOXMhUvAQz
I'm late to the party, but cmux is great. https://t.co/8uuStvqwcm
current split:
codex mac app: knowledege work, learning, reading
cmux + codex cli: coding
Well this one being dismissed as not a security vulnerability is more surprising than the last time as it's a kernel data abort, but so be it. Another iOS 26.5 panic, disclosed here. Enjoy https://t.co/JPWHPyBIiw
Cyanide now supports iOS 26.0-26.0.1 on A18 devices. Tweaks may be even buggier than 18.x, but StatBar & Axon appear to be working so far.
https://t.co/9Z3xB9xweT
We are entering a new era of on-device automation. ✨
Watch Gemma 4 E4B navigate and drive an iOS simulator directly using Argent. Local models can handle complex interactions and software navigation autonomously.