Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • SECURITY OF ONLINE GAMES AND HOW IT CAN BE COMPROMISED
  • Technique

SECURITY OF ONLINE GAMES AND HOW IT CAN BE COMPROMISED

Do Son December 17, 2020 4 minutes read
tech-secu

Online games aren’t new. Consumers have been playing them since as early as the 1990s. However, the market is evolving—games that used to require the computing power of dedicated desktops can now be powered by smartphones, and online gaming participation has skyrocketed.

Online gaming has gone through explosive growth in popularity during the last decade and continues to grow at a great speed. With this growth in popularity and thus in the number of players, the need for security also becomes increasingly clear.

CYBERTHREATS

MMOs are multiplayer video games capable of supporting a large number of players at the same time. They are played over the internet and contain one or more words that persist regardless of the presence of players. In MMOs, players can compete and cooperate, and interact with other people all over the world.

One of the most popular MMORPG out there is Black Desert Online where you can buy Black Desert Silver and items to get stronger in the game.

MMORPG’s are one of the main threat of hackings and scams since it uses currency for buying in-game items and sometimes players get scammed through communication.

A few years ago, cybersecurity scryers predicted that the video gaming industry would be the next big target of cybercriminals. Whether this will come true in the future or not, the average gamer may have little to no idea of what awaits them, much less be prepared for it.

Malware and potentially unwanted programs (PUPs)

Malware and PUPs have been the top-of-mind threats to online gamers and for a good reason. They come in many, many forms—key generators; game cracks; trainers; fake mobile game apps, and game installers consider that every conceivable software related to gaming might have a malicious equivalent in the wild.

Lastly, malware can affect gamers when they connect to infected servers. In the report, Study of the Belonard Trojan, exploiting zero-day vulnerabilities in Counter-Strike 1.6, security experts at Russian antivirus firm Doctor Web investigated Belonard, a Trojan that takes advantage of weaknesses in both Steam and pirated versions of Counter-Strike 1.6 (CS 1.6).

Phishing scams

Steam users are probably more than familiar with the times when phishers used squatted domains to lure them into giving out their credentials to Steam or their favorite third-party trading site, like CS:GO Lounge

sleamcummunity.com and steamcornmunity.com were just two of several new domains that popped up, made to look like a Steam Community page, and used in several campaigns aiming to harvest Steam accounts. We believed that the stolen accounts could be used to lead more Steam users into giving away their credentials as well.

Similarly, a fake CS:GO Lounge domain was registered and mimicked the real trading and bidding site. Criminals behind it were also after Steam credentials. To rub salt to the wound, they even added a Trojan that pretended to be a Steam activation file.

Nowadays, we not only play on consoles or PCs but also our smartphones or tablets. Therefore, we must be careful and pay special attention to those fake apps masquerading as official games, updates, tricks, etc.

Since 2015, there have been various malicious mobile applications masquerading as well-known games, which perform different types of attacks on infected devices. Perhaps one of the most important cases has to do with an Android Trojan hidden among the games at Google Play, which allowed attackers to control devices remotely, thanks to its backdoor capabilities. By imitating games like Plants vs. Zombies 2 or Subway Surfers, it was mainly used to display ads on the compromised device.

WHY Security is needed

Some people may think that security isn’t a big deal when it comes to online gaming. The security of public locations is a big deal because some terrorists might bomb them. Security of a store is a big deal, because people might steal stuff, and a similar thing can be said about the security of digital products, such as software, movies, and music. Spider Solitaire Games are just there for fun and enjoyment, so why is it so important that they are secure as well?

The internet is undergoing explosive growth, bringing along lots of computer security issues. Online games suffer from these problems directly because of the way they are built.

Then there is the economy of World of Warcraft which is huge, and there are many possible ways to transfer real money into and out of the game… Lastly, there is the size of the game’s player base. A game this popular, using this architecture and having such a big economy, is extremely attractive for cheaters, hackers, and even criminals.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: SECURITY OF ONLINE GAMES

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-57496CVSS 9.6
    ## REST Path Traversal Bypasses Token Redaction in netlicensing-mcp ### Summary The `netlicensing_get_product` MCP tool in `netlicensing-mcp` interpolates...
    📅 Updated: Oct 1, 2026
  • CVE-2026-75957CVSS 9.8
    The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass...
    📅 Updated: Oct 1, 2026
  • CVE-2026-15989CVSS 9.8
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in...
    📅 Updated: Oct 1, 2026
  • CVE-2025-66398CVSS 9.6
    Signal K Server is a server application that runs on a central hub in a boat. Prior to...
    📅 Updated: Oct 1, 2026
  • CVE-2025-68620CVSS 9.1
    Signal K Server is a server application that runs on a central hub in a boat. Versions prior...
    📅 Updated: Oct 1, 2026
  • CVE-2025-69943CVSS 9.8
    kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
    📅 Updated: Oct 1, 2026
  • CVE-2025-65340CVSS 9.8
    kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
    📅 Updated: Oct 1, 2026
  • CVE-2025-67403CVSS 9.8
    Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.