Google Chrome is rolling out device-bound session credentials to all users. Session cookies get cryptographically tied to your device, so stolen cookies can't be replayed from a different machine. Attackers who exfiltrate your cookie database get nothing usable.
This is also being done on Twitter. If the person sending you the DM doesn't sound like them, it probably isn't! Always go with your gut. Even if it does sound like them, message them back or call them. If something feels off, DON'T CLICK IT or OPEN IT!
I did not clear this individual. During the time of the PC check, the results were inconclusive until the evidence could be gone over again. After further investigation, it was discovered that this individual had unauthorized software and hardware on their PC resulting in a fail.
POV: You're doing a PC check. It's my 1660 TI bro *sees Radeon GPU installed* As with any new evolution of attack, defenders will find the gaps and will be able to detect it. This isn't the end of competitive gaming.
GPU DMA is the next evolution of traditional DMA technology and is currently working on every anti-cheat platform.
The setup requires an x4 to x16 PCIe splitter and was publicly released by the H-Team. At the moment, it is only compatible with the latest H2 implementation.
Key improvements Features:
โ Full support for multi-function PCIe devices, including GPUs with separate display and audio configuration spaces.
โ Completely rebuilt pass-through core logic for improved stability, cleaner address mapping, and more reliable group binding.
โ New Windows WDDM compatibility adaptations while maintaining native Linux pass-through support.
โ Expanded compatibility across more virtualization and development environments.
The cat-and-mouse game between cheat developers and anti-cheat developers continues.
So Activision, when are you guys going to actually turn everything on in the Azure Attestation portal? I know you all are still testing stuff, but you know it supports DMA, right?
To the threat actor that thought it was funny or fun to deploy numerous webshells on a single server. I really dislike you right now; this is a nightmare. I hope your other shells die and you have to regain access via another exploit.
Unpopular take, but being a cybersecurity consultant is the most exhausting thing mentally. Clients will drain you to the point of no return, and if you don't find a way to manage that stress it will destroy you from the inside out.