Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Red Bull WOLOLO 2026 Takes Over London As Tickets Go On Sale For Eighth Edition: ‘Londinium’

Published

on

Reading Time: 2 minutes

  • Red Bull Wololo returns for its eighth edition, Red Bull Wololo: Londinium, taking place from April 1st – 6th, 2026.
  • The tournament brings together elite Age of Empires strategists from around the globe to battle across Age of Empires II: Definitive Edition and Age of Empires IV.
  • London itself has been transformed into a living Age of Empires spectacle today, with a citywide takeover that lets fans experience the spirit of Age of Empires firsthand.
  • Tickets for the Playoffs are available on eventbrite.co.uk/e/red-bull-wololo-playoffs-tickets-1974965913211?aff=oddtdtcreator
  • Tickets for the Grand Final are available on royalalberthall.com/tickets/events/2026/red-bull-wololo-londinium, giving fans the chance to witness the world’s top Age of Empires players compete in iconic London venues.

The call of “Wololo” rings across the capital of the UK today as tickets officially go on sale for Red Bull Wololo: Londinium, the grandest chapter in Age of Empires competitive history. Taking place from April 1st – 6th, 2026, the renowned esports tournament will not only bring elite RTS competitors to London but transform the city itself in a landmark takeover celebrating the return of Red Bull Wololo for its eighth edition.

To mark the launch of ticket sales, Red Bull Wololo has staged a special takeover across London today, bringing Age of Empires to life in three iconic locations. From Leicester Square and Tower Bridge, to Hyde Park with the Royal Albert Hall rising in the distance, the streets have come alive with performers dressed as iconic characters from the game. Wielding medieval-style flags emblazoned with the Red Bull Wololo emblem, they offered passersby and fans a glimpse into the tournament and the chance to join the action as London beheld the spirit of Age of Empires.

In 2026, across six days of competition, Red Bull Wololo: Londinium will see the world’s best Age of Empires strategists battle for supremacy in Age of Empires II: Definitive Edition and Age of Empires IV, culminating in a historic Grand Final at the Royal Albert Hall – the first-ever Age of Empires orchestrated esports final, with a 40-piece orchestra performing the game’s legendary soundtrack live for over 2,500 fans.

Red Bull Wololo: Londinium Key Dates

  • Group Stages: April 1st – 3rd, 2026 – Red Bull Gaming Sphere, Shoreditch
  • Playoffs: April 4th – 5th, 2026 – The Odeon Luxe Cinema, Leicester Square
  • Grand Final: April 6th, 2026 – Royal Albert Hall

The action kicks off at the Red Bull Gaming Sphere with the Group Stages before moving to the Odeon Luxe in Leicester Square for the Playoffs, where top competitors from the Age of Empires II and Age of Empires IV qualifiers battle under the spotlight in one of London’s most iconic entertainment venues. The tournament will then reach its crescendo within the historic walls of the Royal Albert Hall, where players who have proven themselves worthy will face off for ultimate glory and a place in Age of Empires competitive history.

Tickets are now on sale for the Playoffs and Grand Final of Red Bull Wololo: Londinium. Secure your Playoff tickets (eventbrite.co.uk/e/red-bull-wololo-playoffs-tickets-1974965913211?aff=oddtdtcreator) and Grand Final tickets (royalalberthall.com/tickets/events/2026/red-bull-wololo-londinium) . Don’t miss the chance to see elite esports players from around the world compete across Age of Empires titles in historic venues, as London itself becomes a stage for strategy and conquest.

Fans across the globe will be able to tune into the action for every stage of the tournament via the Red Bull Gaming Twitch and YouTube channels.

 

The post Red Bull WOLOLO 2026 Takes Over London As Tickets Go On Sale For Eighth Edition: ‘Londinium’ appeared first on European Gaming Industry News.

Continue Reading

Latest News

Konami Digital Entertainment and the Confederation of African Football (CAF) Have Signed a Partnership Agreement

Published

on

Reading Time: 2 minutes

Konami Digital Entertainment pleased to announce the signing of a partnership agreement with the Confederation of African Football (CAF).

Konami Digital Entertainment B.V. (Konami) announces a partnership agreement with the Confederation of African Football (CAF) has been signed. CAF is the continental federation governing football associations in the African region, currently comprising 56 member countries and regions. CAF organises numerous tournaments, including the Africa Cup of Nations, which determines the continent’s top football team, significantly contributing to the sport’s development.

In recent years, football has enjoyed overwhelming popularity in Africa, with interest in national and club teams rapidly increasing. Furthermore, interest and enthusiasm for eFootball are also growing, leading to the signing of this new licensing agreement with CAF.

To commemorate this partnership, a special AFRICA CUP OF NATIONS 25 Campaign will be held within eFootball. Tournament events and African star players will appear in the game, allowing players to experience the excitement of the actual tournament.

Koji Kobayashi, Senior Executive Officer, Konami Digital Entertainment commented: “We are delighted to announce the establishment of a partnership with the Confederation of African Football (CAF). This partnership brings new possibilities to the gaming experience, and we are truly excited to deliver the passion of the African region-home to some of the world’s most powerful footballing nations – to fans around the globe through eFootball, and this partnership opens up exciting new possibilities for the gaming experience. Through this initiative, we look forward to adding new African star players and tournament licenses such as TotalEnergies CAF Africa Cup of Nations, further enhancing the realism and excitement of eFootball.”

Véron Mosengo-Omba, General Secretary of the Confederation of African Football (CAF) adds: “The TotalEnergies CAF Africa Cup of Nations Morocco 2025 will be one of the most exciting and widely followed editions of our flagship competition. Our partnership with KONAMI reflects CAF’s commitment to innovation, global fan engagement, and creating new opportunities for African youth in both football and digital spaces.”

Konami Digital Entertainment will continue to expand its licenses and provide authentic soccer experiences to fans worldwide through eFootball.

 

The post Konami Digital Entertainment and the Confederation of African Football (CAF) Have Signed a Partnership Agreement appeared first on European Gaming Industry News.

Continue Reading

Latest News

G2 Announces Betpanda as Official CS Global Betting Partner Ahead of 2026 Season

Published

on

Reading Time: 2 minutes

  • G2 has named Betpanda, a leading online crypto casino, as its official CS global betting partner
  • Starting in 2026, Betpanda will appear on G2’s CS2 team jerseys
  • Throughout the year, fans can take part in tournaments, giveaways, sweepstakes, and a variety of video and social content designed to enhance the fan experience

G2, one of the world’s leading entertainment and esports brands, has entered into a partnership with Betpanda, a leading online crypto casino, as the official global betting partner for the organisation’s Counter-Strike team. The collaboration will roll out a series of initiatives worldwide, including giveaways, sweepstakes, content, tournament activations, and more. As part of the collaboration, Betpanda branding will appear as the main logo on G2’s CS team jerseys from 2026.

Throughout 2026, fans will be able to experience the partnership first-hand at multiple esports tournament activations throughout the year, featuring creators and teams, offering exclusive in-person opportunities.

With a shared commitment to innovation and community, G2 and Betpanda aim to provide engaging experiences for fans throughout the year. The partnership will also extend to a range of digital activations, featuring exclusive video and social content, giveaways, and other initiatives.

“Betpanda joins us at an exciting moment for the organisation,” said Alban Dechelotte, CEO of G2. “This alliance allows us to build fresh, meaningful touchpoints for our fans throughout the year. We hope to create moments that will entertain and connect with fans all around the world.”

“G2 has set the standard for excellence in esports, and we’re proud to collaborate with a team that consistently pushes the boundaries of what the industry can be,” says Betpanda. “Their view on innovation and creativity goes perfectly hand-in-hand with our way of breaking boundaries and reaching new fans and audiences. Thank you to EMW Global for helping us to make this partnership possible. We’re excited to see the impact we can create alongside G2 in 2026”

 

The post G2 Announces Betpanda as Official CS Global Betting Partner Ahead of 2026 Season appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.