โŒ

Normal view

GTA cheat service Atlas Menu hacked as attacker alleges screenshot spying

1 June 2026 at 14:15
Grand Theft Auto cheat users have discovered that even the people selling ways around the rules struggle to follow some basic security ones. According to breach notification site Have I Been Pwned, the operators of Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, suffered a data breach in May that exposed information belonging to tens of thousands of users after an attacker allegedly gained access to the service's systems and dumped its database online. The breach exposed 64,000 unique email addresses, according to HIBP. The leaked data also included usernames, IP addresses, support tickets, and passwords stored as bcrypt hashes. The individual who claimed responsibility for the breach published the stolen database to a public GitHub repository, claiming to have gained access to "all Atlas systems" before extracting customer records, support conversations, menu license keys, signup dates, and Rockstar Games account identifiers. The data, reviewed by The Register, also appears to include lists of thousands of banned users, administrator logs, and other internal records. Posts discussing the breach on Reddit suggest this was not Atlas Menu's first security incident, but users said the latest leak appears to contain significantly more sensitive information than previous disclosures. Anyone signing up for a GTA cheat service probably wasn't expecting privacy guarantees. Even so, having your email address leaked is one thing. Having support tickets, account identifiers, and purchase records dumped onto GitHub is another. The Atlas breach comes weeks after Rockstar Games was pulled into a separate data leak claimed by ShinyHunters. In that case, the extortion crew alleged it had accessed Rockstar data through cloud cost-monitoring platform Anodot and threatened to publish the information unless its demands were met. Atlas users now have their own security headache to deal with. Whether they're more concerned about the leaked database or the screenshot-spying allegation will likely depend on what they were doing while the software was running. ยฎ

โšก Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

1 June 2026 at 13:59
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality. The vibe is simple: old

r/netsec monthly discussion & tool thread

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.

submitted by /u/albinowax
[link] [comments]

Are Your World Cup Tickets Legit? 40% of Fans May Risk Unofficial Sellers

1 June 2026 at 12:45

Whetherย youโ€™reย planning a once-in-a-lifetime trip or just hoping to catch a match whileย itโ€™sย in your city, the 2026 FIFA World Cup is already driving a surge in ticket searches, travel bookings, and last-minute plans.ย 

But where thereโ€™s high demand and big money,ย scammersย arenโ€™tย far behind.ย 

Letโ€™s break down the new McAfee research, what scams to watch for, and how McAfeeโ€™s tools help you stay safe.

New McAfee Research Finds a Gap Between Awareness and Riskย 

New research from McAfee shows that while most fans are aware of World Cup-relatedย scams, many are still willing to take risks to secure tickets.ย ย 

In fact,ย 40% say they would consider buying from an unofficial source if theyย canโ€™tย get tickets throughย theย officialย FIFA site,ย as many expect tickets to sell out and hope to find affordable resale options.ย 

That tension is what makes events like the World Cup especially vulnerable forย scams.ย 

With limited ticket availability, rising prices, and the pressure to act quickly, even informed fans can find themselves making decisions they normallyย wouldnโ€™t, like buying tickets from a reseller on TikTok.ย ย 

And scammers are counting on it.ย 

Survey takeaways:ย 

  • 76% of fans are interested in getting World Cup ticketsย 
  • 35% have already started searching onlineย 
  • 43% are willing to spend over $500 on ticketsย 
  • 66% sayย theyโ€™reย aware of World Cup-relatedย scamsย 
  • 66% sayย theyโ€™reย concerned about beingย scammedย 
  • 40% would consider buying tickets from unofficial sourcesย 

The Most Common World Cup Scams to Watch Forย 

Below is a comprehensive breakdown of the most commonย scamsย tied to major global sporting events like the World Cup, including how they work and what to look for.ย 

McAfeeโ€™sย Scamย Detector,ย ย Safe Browsingย tools,ย VPN, andย Password Managerย work together to help you spotย scamsย like theseย as they happen by flagging suspicious messages, blocking risky websites, and helping you make safer decisions before you click, pay, or share information.ย 

ย โšฝ Scam Typeย  ย  What It Isย  ย  How It Worksย  ย  Red Flagsย 
Fake Ticket Resale Scamย  Fraudulent tickets sold through unofficial sites or individualsย  Scammers create fake listings or duplicate real tickets and sell them to multiple buyersย  Prices far below or above market, refusal to use official transfer systems, pressure to act fastย 
Social Media Ticket Scamย  Tickets sold through platforms like Instagram, Facebook,ย TikTok,ย or Xย  Fake or hacked accounts post โ€œlast-minuteโ€ ticket offers and move conversations to DMsย  Urgent language (โ€œonly 2ย leftโ€), new or suspicious profiles, requests to pay outside the platformย 
Duplicate QR Code Scamย  One legitimate ticket is resold multiple timesย  Multiple buyers receive the same QR code, but only the first scan worksย  Screenshots instead of official transfers, identical tickets sold repeatedlyย 
Fake Ticket Website Scamย  Websites designed to look like official ticket platformsย  Victims enter payment info or purchase tickets thatย donโ€™tย existย  Slightly misspelled URLs, unfamiliar domains, lack of official branding verificationย 
Travel & Accommodation Scamย  Fake hotels, rentals, or travel packagesย  Listings appear legitimate but eitherย donโ€™tย exist or are already bookedย  Prices that seem unusually low, requests for upfront payment, lack of verified reviewsย 
Booking Impersonation Scamย  Fraudsters pose as airlines, hotels, or booking platformsย  Victims receive messages about โ€œissuesโ€ with bookings and are asked to click links or provide infoย  Unexpected messages, requests for login or payment details, links thatย donโ€™tย match official sitesย 
Public Wi-Fi & Phishing Scamย  Data theft through unsecured networks while travelingย  Scammers intercept data or create fake login portals on public Wi-Fiย  Open networks with no password, login pages asking for unnecessary informationย 
Fake Giveaway Scamย  Promotions claiming free tickets or VIP accessย  Victims are asked to enter personal data, click links, or pay โ€œprocessing feesโ€ย  โ€œYouโ€™ve wonโ€ messages youย didnโ€™tย enter, requests for payment to claim prizesย 
Betting & Prediction Scamย  Fake betting tips or โ€œguaranteed winsโ€ tied to matchesย  Scammers sell fake predictions or direct users to malicious betting sitesย  Claims of guaranteed outcomes, requests for upfront payment, unfamiliar platformsย 
Merchandise Scamย  Counterfeit World Cup gear sold onlineย  Buyers receive low-quality or no product at allย  Unverified sellers, poor site quality, deals that seem too good to be trueย 

How AI is Making These Scams More Convincing

Unfortunately, with the continued improvement of AI, theseย scamsย are becoming more convincing.ย 

AI tools allow scammers to create:ย 

  • More realistic websites and messagesย 
  • Personalized outreach that feels legitimateย 
  • Fake endorsements, images, or promotionsย 

That means traditional advice like โ€œlook for typosโ€ is no longer enough on its own.ย 

Todayโ€™sย scamsย often look polished, professional, and believable.ย 

The website shows a scam operation detected by McAfee Labs. It has incredibly realistic seat-selection options and ticket-buying features. But itโ€™s fake.
The website above shows a scam operation detected by McAfee Labs. It has incredibly realistic seat-selection options and ticket-buying features. But itโ€™s fake.
Here you can see just how realistic the website looks. But these tickets are not actually for sale.
Here you can see just how realistic the website looks. But these tickets are not actually for sale.

What โ€œOfficialโ€ Actually Means (and Why It Matters)ย 

For the World Cup, official ticket sales happenย through designated FIFA sales phases and platforms.ย 

Buying outside those channels increases the risk of:ย 

  • Invalid or duplicate ticketsย 
  • Inflated pricing without guaranteesย 
  • No recourse if something goes wrongย 

Even if a ticket looks legitimate, it may be:ย 

  • Sold to multiple buyersย 
  • Already voidedย 
  • Rejected at the gate

When in doubt,ย go directly to the officialย FIFA websiteย instead of clicking links from messages or ads.ย You can alsoย visit their comprehensive FAQ sectionย for all your ticket and event questions.ย 

How to Stay Safe When Buying Tickets or Travelingย 

Here are practical steps fans can take to reduce risk:ย 

Safety Checkย  What To Doย 
Buy from official sourcesย  Use FIFAโ€™s official ticket platform whenever possibleย 
Avoid clicking links in messagesย  Navigate directly to official websites instead.ย McAfeeโ€™s Safe Browing toolsย help prevent you from opening malicious links.ย 
Be cautious with resale offersย  Verify platforms and avoid direct peer-to-peer paymentsย 
Check QR codes before you scan themย  You can check for QR codeย scamsย on-demandย withย Scam Detectorย 
Donโ€™tย pay with untraceable methodsย  Avoid wire transfers, gift cards, or crypto-only paymentsย 
Double-check URLsย  Look for misspellings or unusual domainsย 
Use secure connectionsย  Avoid making purchases on publicย Wi-Fi, orย use aย VPNย like McAfeeโ€™s.ย 
Protect your accountsย  Use strong passwords and enable two-factor authentication. Consider aย password managerย like McAfeeโ€™s.ย ย 
Verify before you buyย  If something feels off, pause and check before sending moneyย 

What to Do If You Thinkย Youโ€™veย Been Scammedย 

If you think you may haveย purchasedย a fraudulent ticket, clicked a suspicious link, or shared information with a scammer, acting quickly can help limit the impact.ย 

Immediate steps to takeย 

Stop communication immediately
Do not sendย additionalย money or information, even if the sender claims you need to โ€œcompleteโ€ a transaction.ย Itโ€™sย alsoย a good ideaย to take screenshots of messages in case the scammer disappears.ย 

Contact your bank or payment provider
Report the transaction as soon as possible. Many institutions can help reverse charges or flag fraudulent activity if caught early.ย 

Secure your accounts
Change passwords for any accounts that may be affected, especially email, banking, and ticketing platforms.ย Ourย password managerย andย free password generatorย helpย create unique passwords every time.ย ย 

Enable two-factor authentication (2FA)
Adding an extra layer of security can help prevent unauthorized access, even if your password was exposed.ย 

Scan your device for threats
If you clicked a suspicious link or downloaded a file, run a security scan to check for malware or malicious software.ย Check out our free security scan.ย 

Monitor for unusual activity
Keep an eye on financial accounts, email logins, and any services tied to your personal information.ย Our free WebAdvisorย helps protect you from malware and phishing attempts while you surf.ย 

The image above shows malicious apps masquerading as sports betting sites or promising unique World Cup coverage. But when users download, their devices are infected.
The image above shows malicious apps masquerading as sports betting sites or promising unique World Cup coverage. But when users download, their devices are infected.

How McAfee Helps You Spot Scams in the Momentย 

McAfee offers more than traditional antivirus, combining multiple layers of digital protection in one app to help you stay safer while searching, clicking, and buying online.ย 

Scam Detectorย helps flag suspicious texts, emails, and videos automatically,ย so you can spot aย scamย before it hits you and your walletย 

Safe Browsing toolsย help block risky websites, alert you to phishing attempts, and guide you away from malicious linksย 

VPNย helps keep your connection private on public Wi-Fi, protecting your personal and payment informationย 

Password Managerย helps create and store strong, unique passwords to reduce the risk of account takeoverย 

Identity Monitoring and Alertsย notify youย if your personal information appears where itย shouldnโ€™t, so you can quickly take steps to fix itย 

Personalย info removalย helps find and remove your personal infoย from dataย broker sitesย and close out old forgotten accountsย 

Device and Account Securityย helps protect the devices and accounts you use every dayย 

Finalย Thoughtsย 

The World Cupย isnโ€™tย just another event,ย itโ€™sย a moment when millions of people are making fast decisions involving real money, travel plans, and personal information.ย 

What McAfeeโ€™s research makes clear is that the biggest riskย isnโ€™tย a lack of awareness. Most fans already knowย scamsย exist.ย The risk is what happens next.ย 

When tickets are scarce, prices are high, and the pressure to act is real, even informed consumers may take chances they normallyย wouldnโ€™t.ย Thatโ€™sย where scammers succeed: not by tricking people whoย arenโ€™tย paying attention, but by catching people in moments of urgency.ย 

As demand continues to build toward the tournament, more fans will be searching, comparing, andย purchasingย online.ย ย 

The takeaway is simple:ย Staying safeย isnโ€™tย just about knowingย scamsย exist.ย Itโ€™sย about slowing down, verifying before you buy, and using tools that help you make informed decisions in the moment.ย 

*McAfee is not affiliated with or endorsed by FIFA.ย 

The post Are Your World Cup Tickets Legit? 40% of Fans May Risk Unofficial Sellers appeared first on McAfee Blog.

Palo Alto VPN bug graduates from advisory to active exploitation

1 June 2026 at 12:15
Palo Alto customers are being been told to patch yet another internet-facing security flaw after researchers caught attackers bypassing GlobalProtect authentication and gaining unauthorized VPN access. The flaw, tracked as CVE-2026-0257, affects PAN-OS deployments using GlobalProtect authentication override cookies under specific configurations. Palo Alto disclosed the bug on May 13 and initially assigned it a medium-severity rating, saying it was aware of attempts to exploit it but had not observed any malicious exploitation. That assessment has not aged well. Security boffins at Rapid7 said they observed successful exploitation across multiple customer environments dating back to at least May 17 and validated the attack technique using its own proof-of-concept testing. Attackers established unauthorized VPN sessions on vulnerable systems, potentially granting access to internal corporate networks without legitimate credentials, it added. Rapid7's analysis suggests the flaw comes down to how PAN-OS trusts authentication override cookies. In certain deployments, hackers can create their own cookies and have the firewall accept them as legitimate. The risk is highest where the same certificate is used for both HTTPS services and authentication override cookies, giving the baddies access to the information needed to generate convincing fakes. Rapid7 said it observed multiple waves of activity targeting vulnerable devices. In some cases, cybercrims successfully obtained VPN IP addresses and network access, but the company said it didnโ€™t observe evidence of successful lateral movement following initial access in the incidents it investigated. The flaw has now landed in CISA's Known Exploited Vulnerabilities catalog, with federal agencies given until June 1 to patch or otherwise secure affected systems. Palo Alto has also revised its advisory, elevating the severity rating and attaching its highest urgency label. Fixes are available for supported releases. "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied," the firm said in an update. The latest PAN-OS headache arrives less than a month after another Palo Alto emergency. In May, state-backed attackers were found exploiting CVE-2026-0300, a critical remote code execution flaw in the PAN-OS User-ID Authentication Portal, before patches became widely available. Organizations running vulnerable GlobalProtect gateways now face a familiar choice: patch quickly or find out whether someone else gets there first.ยฎ

Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection

1 June 2026 at 12:00
Announcing the new integration between Cisco Secure Access and Microsoft Purview designed to provide unified DLP based on Purview policies that can be enforced locally and in the cloud within Cisco Secure Access.

Cisco Secure Access and Island Browser Enable Zero Trust Everywhere

1 June 2026 at 12:00
The integration between Cisco Secure Access and Island enterprise browser improves the user experience while reducing risk by connecting and protecting user access to private applications from unmanaged devices.

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

1 June 2026 at 11:54
A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors. The activity entails distributing spear-phishing emails containing ZIP attachments

The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

1 June 2026 at 11:30
Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more precise name for what MSPs and MSSPs need from the software

Password manager Dashlane suspends customer accounts amid brute-force attacks

1 June 2026 at 11:15
Password manager Dashlane has disabled a number of user accounts as a precaution amid a spate of brute force attacks. It didn't specify the scale of the attack, although scores of users have queried the reason for receiving emails informing them of account suspensions. โ€œYour account has been temporarily suspended for security reasons as someone has attempted to register a new device and didn't enter the correct token after several tries,โ€ the emails read, along with instructions to contact customer support to restore access. The attacks began on Sunday afternoon and the Dashlane team said it had finished investigating the matter later that evening, restoring all affected user accounts in the process, according to its status page. In a copy-paste statement sent to a number of users via social media, Dashlane also confirmed there was no compromise of internal systems. Dashlane posted an update to its status page on Monday morning, repeating the same statement from a day earlier, but changing the incident status from "resolved" to "monitoring." Several users reported unauthorized login attempt notifications from various countries - the common culprits being Korea and Russia. Dashlane did not specify whether any attempts on customer accounts were successful. Dashlaneโ€™s interventions involved suspending accounts and its two-factor authentication (2FA) service. Some users reported trying to access Dashlaneโ€™s 2FA one-time passcodes, but when entering them, all that returned was an error. Some criticised the company for a lack of public comms about the attacks. Aside from the direct account suspension emails and some replies to users on social media, Dashlane has not disclosed the attack through any high-visibility channels. Users also queried whether the initial account suspension emails were a phishing attempt. But the emails showed no hallmarks of phishing as they contained no suspicious links, no attachments and were sent from a real Dashlane domain. However, the nature of the message and the fact that the emails contained an old Dashlane logo only exacerbated some customersโ€™ fears. The Register has contacted Dashlane for more information. ยฎ

Putin sends submarines to survey Britain's subsea cables. UK deploys Royal Navy, mobilizes parliamentary draftsmen

1 June 2026 at 10:48
The British government wants stronger protection for subsea internet cables following a surge in Russian activity near UK waters, but its latest proposals lean heavily on fines and prison sentences rather than direct defensive action. Plans - outlined in a speech by Baroness Liz Lloyd, Minister for Digital Economy ahead of a consultation - include tougher penalties for recklessly damaging undersea cables, operator security obligations and emergency powers allowing government to compel businesses to better protect their infrastructure. In April, the Royal Navy and Royal Air Force tracked Russian submarines on a covert reconnaissance near critical undersea infrastructure. According to reports, Russia deployed an Akula-class attack submarine as a decoy while two specialist vessels from Directorate of Deep Sea Research - known as Glavnoye Upravlenie Glubokovodnikh Issledovanii (GUGI) - surveyed the UK's cable routes. โ€œTheir mission was to survey our cables in peacetime, so they could more easily sabotage them in a conflict,โ€ Lloyd said in a speech delivered at the Royal United Services Institute (RUSI). โ€œThey wanted this operation to be secret, but they failed." In light of this, the government is reviewing whether the UKโ€™s security and resilience arrangements are strong enough, the Defence, Science and Technology Laboratory said. UK Parliament's Joint Committee on National Security Strategy (JCNSS) last year told the government it is "too timid" in its approach to protecting Britainโ€™s cable connections, and must do a better job. Measures proposed include tightening the law so ship owners and operators that recklessly damage subsea internet cables face tougher penalties. Cable operators could be landed with extra obligations to ensure they take steps to prevent, detect and respond to security incidents in a consistent and timely manner. โ€œThe UK already has strong protections in place for our subsea cables, but in a more uncertain world we cannot stand still,โ€ said Lloyd. "As hostile activity by Russia and others grows, protecting these cables matters more than ever for our economy, security and daily lives.โ€ Some 64 cables connect Britain to the global internet, and when one breaks, repair vessels are typically on scene within eight days. Historically, most cable faults have stemmed from fishing activity or dragging anchors, not sabotage. The Royal Navy unveiled its Atlantic Bastion program last year to supplement its sub-hunting ships with a force of uncrewed, autonomous vessels. The aim is that enemy submarines in the North Atlantic have nowhere to hide. This is in its early stages, with ยฃ14 million committed so far for testing and development. The latest proposals will be outlined a white paper published later this year. Separately, the UK, US, and Australia announced this weekend that their AUKUS partnership will jointly develop sensor and weapons payloads for uncrewed underwater vehicles, which is another building block for protecting seabed infrastructure. ยฎ

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

1 June 2026 at 09:31
Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository. What

โŒ