reverse engineering

AppWizard
September 16, 2026
Denuvo has filed a lawsuit against an individual known as "voices38" for allegedly tampering with and bypassing its anti-piracy technology, which is used in various popular PC games. The lawsuit was initiated in the U.S. Northern District Court of California, claiming violations of the Digital Millennium Copyright Act (DMCA). Denuvo describes voices38 as a "computer hacker" who has cracked numerous games, including titles like Doom: The Dark Ages and Hogwarts Legacy. Voices38 responded casually on Reddit, indicating a lack of concern for the lawsuit. Denuvo's business model relies on selling DRM solutions, and while it cannot sue for copyright infringement, it claims to be harmed by voices38's activities. The lawsuit lists several games that voices38 has allegedly cracked and marks Denuvo's first legal action against a video game pirate in the U.S. The company is also attempting to uncover voices38's true identity and may file subpoenas to gather more information. Public sentiment appears to be against Denuvo, with criticism regarding its software's impact on legitimate users.
AppWizard
August 12, 2026
Xodus is an open-source project aimed at enabling Linux and macOS users to access Xbox PC and PC Game Pass subscriptions without Windows. Developed by the team behind the Heroic Game Launcher, Xodus builds on existing functionalities to allow gameplay from various platforms. The project has successfully created an Xbox authorization system for users to log in, verify licenses, and identify available Game Pass titles. However, challenges remain in launching games, requiring reverse engineering of Microsoft technologies like the Game Development Kit (GDK) and MSIXVC format. Compatibility issues are anticipated, particularly with older Universal Windows Platform (UWP) games, such as Forza Horizon 3. Additionally, launching games will necessitate the use of Linux technologies like Wine, DXVK, or VKD3D-Proton, complicating full compatibility with the Game Pass catalog.
AppWizard
August 10, 2026
Project Xodus is an open-source initiative focused on reverse-engineering Xbox PC and Game Pass titles to enable their use on Linux and Mac systems. The project has made significant progress in Microsoft authentication and package decryption, allowing Linux users to download and process Xbox subscription games locally. The team has successfully reverse-engineered Microsoft’s identity services and license verification systems, unlocking encrypted MSIXVC game files and enabling the verification of game licenses and decryption of installation packages on non-Windows operating systems. Xodus serves as a translation bridge for Microsoft’s proprietary ecosystem services, providing custom proxy libraries for games to function as if they are running in a native Windows environment. It specifically targets modern games built on Microsoft’s GDK framework, excluding older titles using the Universal Windows Platform and those dependent on kernel-level anti-cheat mechanisms. The project aims to improve access to Xbox Game Pass on devices like the Steam Deck by facilitating direct local hardware execution, reducing reliance on cloud streaming and enhancing portable gaming experiences. Community feedback has been positive, with developers actively sharing updates and engaging with inquiries.
AppWizard
July 26, 2026
Microsoft has released four original Xbox titles for PC, enhancing its gaming ecosystem and aligning with its commitment to backwards compatibility. These titles are packaged as standard Games on Demand (GOD) files, which can be converted into base ISOs using GOD extractors. The company has utilized a native x86 version of its Xbox 360 emulator, Xe03, to facilitate this transition. Xe03 is integrated into Xbox One and Xbox Series consoles for backwards compatibility and allows modern consoles to run original Xbox titles. The recent PC port of Xe03, combined with components from projects like XWine1, enables the running of dumped backwards-compatible Xbox 360 and original Xbox games. Among the released titles is Fuzion Frenzy, and Microsoft plans to expand its library of backwards-compatible titles for PC. The PC version of Xe03 enhances the original 480p output of OG Xbox games to 4K and includes features like built-in V-Sync and enhanced anti-aliasing. These games are available through the Xbox PC app under the Xbox Anywhere program, allowing users with digital licenses on console to access them for free on PC. Microsoft is also set to introduce Xbox Achievements support for these titles.
Winsage
July 11, 2026
Microsoft is advocating for a reevaluation of Windows patch management practices due to the rapid evolution of artificial intelligence (AI) impacting cybersecurity. The company emphasizes that traditional timelines for patch deployment, typically spanning several weeks after the monthly Patch Tuesday, are inadequate against modern cyber threats. Microsoft recommends organizations shorten deployment windows to under three days for quality updates, with immediate installation deadlines and minimal user grace periods. To support these changes, Microsoft is enhancing Windows Autopatch with a new reporting dashboard for patch compliance and security insights. The company is promoting cloud-managed deployment through Microsoft Intune and Windows Autopatch while continuing to support legacy tools. Additionally, Microsoft is introducing Windows Hotpatch technology, allowing security updates to be installed without immediate reboots, and advocating for the use of identity-based access controls to isolate unpatched devices. The guidance reflects a shift from scheduled patching to continuous risk management, encouraging organizations to prioritize high-risk assets and automate update deployments. Microsoft is also investing in AI-assisted vulnerability discovery and automated code analysis to improve defensive capabilities. The overarching message is that enterprises must adapt their update strategies to address the accelerated pace of AI-driven exploitation.
Tech Optimizer
July 10, 2026
Cybercriminals are exploiting the VLC media player to install ValleyRAT, a remote access trojan, by embedding malware in a seemingly harmless file linked in phishing emails. The attack starts with an email that prompts the victim to download a ZIP archive containing a fake VLC executable and a malicious DLL named libvlc.dll. This method uses DLL sideloading to execute the malware under the guise of a legitimate application. Once executed, the malware establishes persistence by creating a registry entry and connects to a remote server to retrieve the final payload. ValleyRAT employs evasion tactics to avoid detection, including assessing system characteristics before executing harmful actions and using a fileless approach to deliver the payload directly into memory. Researchers have identified indicators of compromise, including specific SHA1 hashes and URLs associated with the malicious campaign.
Tech Optimizer
July 3, 2026
Cybercriminals are using a sophisticated method to bypass security measures by embedding malware within the VLC media player. This campaign exploits VLC to install ValleyRAT, a remote access trojan, through phishing emails that contain links to download a seemingly harmless file. Once the file is opened, it activates a hidden backdoor that evades detection by antivirus solutions. The malware has been active since 2023, with a significant increase in activity noted through 2025 and into 2026, particularly targeting Chinese and Japanese-speaking users. The infection process begins when a victim clicks a link in a phishing email, leading to a ZIP archive containing a disguised executable and a malicious DLL (libvlc.dll). The executable mimics a legitimate VLC file, and when executed, it loads the DLL, allowing the malware to run under the guise of VLC. The malware establishes persistence by creating a registry entry and connects to a remote server to retrieve the final payload. ValleyRAT employs evasion tactics to avoid detection, such as performing checks on system behavior and using a fileless approach to inject its payload directly into memory, avoiding storage on disk. Researchers recommend training employees to recognize suspicious filenames and deploying endpoint detection tools to identify DLL sideloading behavior. For organizations affected by this campaign, isolating compromised systems and reviewing security logs are critical initial steps. Indicators of compromise include a malicious email domain, a ZIP archive containing a fake VLC executable, and a download URL for ValleyRAT.
Search