XCLUB-COOL STUFF AROUND YOU

 找回密码
 Register
查看: 76|回复: 4
打印 上一主题 下一主题

Electronic Arts Origin gaming client hit by vulnerabilities, says Check Point Research

[复制链接]

4125

主题

2万

帖子

3万

积分

Content Partner

Rank: 8Rank: 8

Tech Fans2020PL KINGHappy children's dayEid PartyHot PartyHappy Easter Medal.pngPOP OUTHug Day MedalKiss Day MedalPropose Day MedalRose Day Medalcouple medalXClub Best Look4.0xclub2019Xclub Kolpost star1post star2post star3post star4sign star1sign star2sign star3sign star4post star5X'Club badge exclusive for Indiasign star5

跳转到指定楼层
#1
发表于 2019-06-28 20:32:03 来自手机 | 只看该作者 |只看大图 回帖奖励 |倒序浏览 |阅读模式
Check Point and CyberInt strongly advise users to enable two-factor authentication and only use the official website when downloading or purchasing games.[br][br][br] [br][br][br]Check Point Research, the Threat Intelligence arm of Check Point Software Technologies, and CyberInt, the leading cybersecurity provider of managed threat detection and mitigation services to digital consumer businesses, identified a chain of vulnerabilities in the Origin gaming client developed by Electronic Arts (EA). Once exploited, the vulnerabilities would have led to player account takeover and identity theft.[br][br]EA is the world’s second-largest gaming company and features a number of household gaming titles such as FIFA, Madden NFL, NBA Live, UFC, The Sims, Battlefield, Command and Conquer and Medal of Honor in its portfolio. The games utilise the Origin client gaming platform, which allows users to purchase and play EA’s games across PC and mobile. Origin contains social features such as profile management, networking with friends via chat, and direct game joining. It also includes community integration with sites such as Facebook, Xbox Live, PlayStation Network, and Nintendo Network.[br][br]CyberInt and Check Point researchers disclosed the vulnerabilities to EA in accordance with coordinated vulnerability disclosure practices to fix the vulnerabilities and roll out an update before threat actors exploit them. They combined their expertise to support EA in developing the fixes to further protect the gaming community. The vulnerability EA closed could have allowed a threat actor to hijack a player’s session, resulting in account compromise and takeover. Protecting our players is our priority," said Adrian Stone, Senior Director, Game and Platform Security at Electronic Arts. "As a result of the report from CyberInt and Check Point, we engaged our product security response process to remediate the reported issues. Working together under the tenet of Coordinated Vulnerability Disclosure strengthens our relationships with the wider cybersecurity community and is a key part of ensuring our players stay secure."[br][br]The vulnerabilities found in EA’s platform did not require the user to hand over any login details whatsoever. Instead, it took advantage of abandoned subdomains and EA Games’ use of authentication tokens in conjunction with the OAuth Single Sign-On (SSO) and TRUST mechanism built into EA Games’ user login process. “EA’s Origin platform is hugely popular; and if left unpatched, these flaws would have enabled hackers to hijack and exploit millions of users’ accounts,” said Oded Vanunu, Head of Products Vulnerability Research for Check Point. "Along with the vulnerabilities we recently found in the platforms used by Epic Games for Fortnite, this shows how susceptible online and cloud applications are to attacks and breaches. These platforms are being increasingly targeted by hackers because of the huge amounts of sensitive customer data they hold."[br][br]"CyberInt provides continuous, automated early detection, taking the attacker’s perspective to enable companies to protect their customers and business proactively,” said Itay Yanovski, Co-Founder and SVP Strategy for CyberInt Technologies. “Gaming goods are traded in official and unofficial marketplaces in the darknet, which makes attacks against gaming studios very lucrative. We believe the cybersecurity industry has the responsibility to protect people, so we make sure to alert the industry with threat-centric security research on newly detected adversary campaigns, such as the recent TA505 – to ensure that the most effective detection and mitigation measures are taken."[br][br]Check Point and CyberInt strongly advise users to enable two-factor authentication and only use the official website when downloading or purchasing games. Parents should create awareness among their children around the threat of online fraud, that cybercriminals will do anything to gain access to personal and financial details, which may be held as part of a gamer’s online account. Check Point and CyberInt encourage gamers to always be vigilant when receiving links sent from unknown sources.[br][br]Source : timesnownews. com
回复

使用道具 举报

3万

主题

16万

帖子

20万

积分

Super CP

sign star1post star1sign star2X'Club badge exclusive for Ghana post star2sign star3Xclub Kol

#2
发表于 2019-06-28 20:44:08 来自手机 | 只看该作者
nice share bro
回复

使用道具 举报

3712

主题

3万

帖子

4万

积分

Security Supervisors

Rank: 8Rank: 8

Happy children's dayHot PartyDiamondKiss Day MedalTeddy Day MedalACTIVE STAR4.0xclubXCLUB TOP FAN photographers2019post star1post star2post star3post star4sign star1sign star2sign star3sign star4post star5X'Club badge exclusive for Indiasign star5

#3
发表于 2019-06-28 23:03:35 来自手机 | 只看该作者
good info share.
回复

使用道具 举报

1712

主题

1万

帖子

2万

积分

Golden Star LV30

Happy children's dayDiamondsign star1sign star2sign star3post star1post star2post star3post star4sign star4X'Club badge exclusive for India

#4
发表于 2019-06-28 23:09:10 来自手机 | 只看该作者
nice share
回复

使用道具 举报

5736

主题

2万

帖子

3万

积分

Jade Diamond LV36

ACTIVE STAR2019post star1post star2sign star1sign star2sign star3post star3post star4post star5sign star4X'Club badge exclusive for India

5#
发表于 2019-06-29 00:33:05 来自手机 | 只看该作者
nice share
回复

使用道具 举报

高级模式
B Color Link Quote Code Smilies |上传

本版积分规则

Infinix Official Website|Infinix official mall|infinix Note 4|XCLUB-COOL STUFF AROUND YOU

GMT+8, 2025-01-12 18:07 , Processed in 0.036985 second(s), 23 queries .

Powered by Discuz! X3.4

© 2001-2017 Comsenz Inc.

快速回复 返回顶部 返回列表