Tag: Security

  • GTA 6 leaks trigger a federal lawsuit and a wave of malware scams

    Real gameplay footage has continued leaking from an account calling themselves Cyberleek, including one clip that appears to prove the leaker has live control over an actual playable build of the game. Take-Two responded with federal DMCA subpoenas against both Microsoft and Discord, approved by a New York court, and both companies have until September 4 to comply.

    The leaker, meanwhile, has started teasing additional footage, including strip club gameplay, in exchange for donations to their cryptocurrency wallet, which tells you most of what you need to know about the actual motive behind this.

    Separately, and more urgently for players, the leaks have triggered a wave of fake “playable build” downloads circulating on Discord and torrent sites. These carry infostealers and remote access trojans disguised as leaked game files, with some listings claiming file sizes over 100GB. Fake Rockstar Social Club login pages are also circulating to phish credentials.

    The bottom line is worth repeating clearly: there is no public GTA 6 build, no beta, and no PC version right now, period. The game launches November 19 on PS5 and Xbox Series X|S only. Anything claiming otherwise, a download, a beta invite, an early access key, is malware or a phishing attempt.

    If you want a general layer of protection against phishing attempts like this, we use and are an affiliate for NordVPN, its built-in threat protection blocks known phishing and scam sites in real time, before you’re able to enter a password or lose money. It’s currently offering 75 percent off two-year plans.

  • August Patch Tuesday fixes a kernel flaw

    August Patch Tuesday fixes a kernel flaw

    This month’s Windows update, KB5121003, includes the usual round of quality-of-life additions, Voice Isolation for Voice Access, better file size display in File Explorer, external fingerprint reader support for Windows Hello, but it also quietly patches something more serious: CVE-2026-68820, a kernel-level vulnerability that North Korea’s Lazarus Group has been actively exploiting since early July.

    The campaign has specifically targeted defense-sector workers using fake job offers as the entry point. It’s worth being precise about the actual risk here: exploiting this flaw requires an attacker to already have some level of access to your machine, so it’s not a drive-by threat that puts the average PC gamer at risk just by browsing normally.

    That said, it’s a confirmed, actively exploited vulnerability, not a theoretical one, and Microsoft’s own advisory recommends installing the update within three days rather than waiting. Even outside the specific threat of these patches, keeping current on security updates is good practice regardless.

    One more date worth flagging while you’re checking for updates: Windows 11 24H2 Home and Pro editions reach the end of updates on October 13, 2026. If you haven’t moved to 25H2 yet, now is a reasonable time to start planning for it rather than waiting until the deadline.

  • Valve confirms Steam hardware data breach affecting EU customers

    Valve confirms Steam hardware data breach affecting EU customers

    Valve confirmed this week that a cyberattack on CEVA Logistics, its European shipping partner, exposed the names, addresses, phone numbers, and order details of customers who bought Steam Deck, Steam Machine, or Steam Controller hardware.

    The attack took place between July 29 and August 1, and Valve began notifying affected customers on August 10.

    Passwords, Steam Guard codes, and payment information were not part of the breach. That’s the important distinction here, this isn’t an account compromise. But the exposed data, real names, real addresses, real order details, is exactly what makes phishing attempts convincing.

    A scam message that correctly references your actual order number or shipping address is far more likely to be trusted than a generic one.

    If you’ve purchased Steam hardware recently, the practical advice is simple: treat any unexpected email, text, or phone call referencing your order as suspicious by default, even if the details check out. Valve will not ask for your password, payment information, or Steam Guard codes through any of these channels.

    If you’re unsure whether a message is legitimate, go directly to Steam’s support site rather than clicking a link or calling a number provided in the message itself.

    If you want a general layer of protection against phishing attempts like this, I use and am an affiliate for NordVPN, its built-in threat protection blocks known phishing and scam sites in real time, before you’re able to enter a password or lose money. It’s currently offering 75 percent off two-year plans.