risks

AppWizard
April 30, 2026
A new infostealer malware called LofyStealer is targeting the gaming community, particularly Minecraft players, by disguising itself as a cheat tool named “Slinky.” It employs a two-stage attack to extract sensitive information from eight major web browsers, including Chrome and Firefox, while evading detection by security software. The malware siphons off cookies, saved passwords, payment card information, and session tokens. Researchers at Zenox.ai identified LofyStealer, linking it to the Brazilian cybercrime group LofyGang, which has been active since October 2022. The malware uses social engineering tactics to appear legitimate and operates as a Malware-as-a-Service platform, offering both Free and Premium tiers to buyers. Its technical sophistication is evident in its method of in-memory browser injection, which allows it to bypass security defenses. The stolen data is compressed and sent to a command-and-control server. Users are advised to avoid downloading unofficial game mods and enable multi-factor authentication to reduce the risk of credential theft. Security teams should monitor for specific behavioral indicators related to the malware's operations.
Winsage
April 30, 2026
Attackers are exploiting CVE-2026-32202, a zero-click vulnerability in Windows Shell, allowing authentication of victims' systems without user interaction. This vulnerability stems from an incomplete patch for CVE-2026-21510 and has been used by the APT28 group with weaponized LNK files to bypass Windows security. Although Microsoft addressed these vulnerabilities in February 2026, the risk remains as opening a folder with a malicious LNK file can still connect victims' machines to the attacker's server, initiating an NTLM authentication handshake that exposes the victim’s Net-NTLMv2 hash. This affects various versions of Windows 10, 11, and Windows Server. Microsoft released a patch for CVE-2026-32202 on April 14, 2026, but did not label it as actively exploited until more than two weeks later, leaving security teams unaware of its urgency. Organizations are advised to apply the patch and consider blocking outbound SMB traffic to mitigate risks.
AppWizard
April 29, 2026
EA CEO Andrew Wilson stated that AI is intended to enhance existing roles in the gaming industry rather than replace them. He emphasized that AI serves as a tool to improve productivity, particularly in routine tasks, and mentioned that EA is hiring more quality assurance (QA) staff than ever before, with 85% of QA work being supported by machine learning or AI-driven algorithms. Despite recent layoffs at EA, including teams involved in the development of Battlefield 6, Wilson maintains that AI's role is primarily augmentation. However, the company faced criticism after allegations that AI was used to generate artwork for a premium bundle, raising concerns about the impact of AI on employment in the gaming sector.
AppWizard
April 29, 2026
The skull-and-bones community has declared that there are no games utilizing Denuvo that remain uncracked or bypassed. The MKDev collective and DenuvOwO developed a hypervisor-based bypass (HVB) in late 2025, which intercepts Denuvo's verification checks. The cracker voices38 successfully removed Denuvo from several titles, including Resident Evil: Requiem. Denuvo has since implemented a 14-day mandatory online check for certain games, complicating the HVB method. The latest version of HVB requires users to disable Core Isolation and Driver Signature Enforcement to run games. The community includes notable figures like repacker FitGirl, who has acknowledged the collaborative efforts of DenuvOwO and voices38.
AppWizard
April 29, 2026
Neverway is a life simulation game developed by Coldblood Inc., where players assume the role of Fiona, a newcomer on a mysterious island. The game features resource gathering, romantic relationships, and confrontations with menacing creatures, alongside a darker narrative involving a potentially malevolent Lovecraftian entity. It combines elements of horror, RPG mechanics, and soulslike gameplay, distinguishing itself from similar titles like Stardew Valley. The game's narrative explores serious themes, including Fiona's struggles with depression, and incorporates a unique color palette that enhances its eerie atmosphere. Neverway is set to release in October 2026, with a Prologue demo currently available on Steam.
AppWizard
April 28, 2026
Every non-VR game utilizing Denuvo DRM has been successfully compromised due to the emergence of the Hypervisor bypass, a method that deceives Denuvo into believing it is functioning correctly. This technique requires users to disable Driver Signature Enforcement, raising security concerns. The CrackWatch subreddit reports that all non-VR Denuvo games have been cracked or bypassed to some degree, with Capcom's Pragmata being completely bypassed just two days before its official launch. Cracking Denuvo within the first week of a game's release can lead to revenue losses of up to 20% for developers and publishers. Irdeto is actively developing updated security versions to address the Hypervisor bypass, assuring that these measures will not compromise game performance.
AppWizard
April 28, 2026
The new Steam Controller lacks native Windows drivers, making it dependent on the Steam application for functionality. This means it cannot be used effectively with games from other platforms like the Epic Games Store or Xbox Game Pass, as it cannot interface with locked files on Windows 11. Gamers wanting to play titles like Forza Horizon 6 via Game Pass must purchase them directly from Steam to use the controller. While Valve could release standard Windows drivers to address this issue, there is skepticism about their willingness to do so. The gaming community previously developed a tool called GlosSI to enable the original Steam Controller to work with non-Steam applications, and a similar solution may emerge for the new model.
Search