Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

user

Discord customer service data breach leaks user info and scanned photo IDs
Gaming Gear

Discord customer service data breach leaks user info and scanned photo IDs

by admin October 3, 2025


One of Discord’s third-party customer service providers was compromised by an “unauthorized party,” the company says. The unauthorized party gained access to “information from a limited number of users who had contacted Discord through our Customer Support and/or Trust & Safety teams” and aimed to “extort a financial ransom from Discord.” The unauthorized party “did not gain access to Discord directly.”

Data potentially accessed by the hack includes things like names, usernames, emails, and the last four digits of credit card numbers. The unauthorized party also accessed a “small number” of images of government IDs from “users who had appealed an age determination.” Full credit card numbers and passwords were not impacted by the breach, Discord says.

The company is notifying impacted users now over email. If your ID might have been accessed, Discord will specify that. Discord also says it revoked the support provider’s access to Discord’s ticketing system, has notified data protection authorities, is working with law enforcement, and has reviewed “our threat detection systems and security controls for third-party support providers.”



Source link

October 3, 2025 0 comments
0 FacebookTwitterPinterestEmail
Microsoft Entra ID hero image
Gaming Gear

This serious Microsoft Entra flaw could have let hackers infiltrate any user, so patch now

by admin September 22, 2025



  • Actor tokens allowed cross-tenant impersonation without logging or security checks
  • CVE-2025-55241 enabled Global Admin access via deprecated Azure AD Graph API
  • Microsoft patched the flaw in September 2025; actor tokens and Graph API are being phased out

Security researchers have found a critical vulnerability in Microsoft Entra ID which could have allowed threat actors to gain Global Administrator access to virtually anyone’s tenant – without being detected in any way.

The vulnerability consists of two things – a legacy service called “actor tokens”, and a critical Elevation of Privilege bug tracked as CVE-2025-55241.

Actor tokens are undocumented, unsigned authentication tokens used in Microsoft services to impersonate users across tenants. They are issued by a legacy system called Access Control Service (ACS) and were originally designed for service-to-service (S2S) authentication.


You may like

Deprecating and phasing out

According to security researcher Dirk-jan Mollema who discovered the flaw, these tokens bypass standard security controls, lack logging, and remain valid for 24 hours, which makes them exploitable for unauthorized access without detection.

Mollema demonstrated that by crafting impersonation tokens using public tenant IDs and user identifiers, he could access sensitive data and perform administrative actions in other organizations’ environments.

These actions included creating users, resetting passwords, and modifying configurations – all without generating logs in the victim tenant.

“I tested this in a few more test tenants I had access to, to make sure I was not crazy, but I could indeed access data in other tenants, as long as I knew their tenant ID (which is public information) and the netId of a user in that tenant,” Mollema explained.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

As it turns out, Azure AD Graph API, a deprecated system that’s slowly being phased out, was accepting the tokens from one tenant and applying them to another, bypassing conditional access policies and standard authentication checks.

Mollema reported the issue on Microsoft, which acknowledged it in mid-July 2025, and patched within two weeks. CVE-2025-55241 was given a severity score of 10/10 (critical), and was officially addressed on September 4.

Azure AD Graph API is being deprecated, while the tokens, which Microsoft refers to as “high-privileged access” mechanisms used internally, are being phased out.

Via BleepingComputer

You might also like



Source link

September 22, 2025 0 comments
0 FacebookTwitterPinterestEmail
Roblox
Esports

Discord raises user count to allow 25M people in a single server

by admin September 5, 2025



Discord has raised the maximum default server limit to 25 million users, just two months after increasing it to 2.5 million.

In July 2025, the platform expanded its cap from 500,000 to 2.5 million. Now, the ceiling has been pushed even further, allowing some of the largest online communities to grow significantly larger.

According to Discord, the update is paired with technical improvements aimed at reducing strain on massive servers. These include batching certain server updates and shifting more processes to asynchronous operations.

Article continues after ad

“In our July 2025 Patch Notes entry (only two months ago!), we mentioned that we increased the default user limit for servers from 500K to 2.5M,” they said.

“Well… we pushed that even *further* and have now bumped that limit to 25 million users. We also continued to solve larger server pain points by batching certain types of server updates and moving to more asynchronous operations to help bring more stability to large servers.

Article continues after ad

“We’re committed to providing a great experience for our users, and we’re hoping this work is felt by users and admins of very large servers.”

Article continues after ad

Stability for larger servers

Discord said the changes are meant to improve stability and create a smoother experience for users and administrators running large-scale communities.

The company noted in its announcement that the expansion is part of an ongoing effort to solve pain points for servers operating at a massive scale, emphasizing its commitment to supporting the growth of major online hubs.



Source link

September 5, 2025 0 comments
0 FacebookTwitterPinterestEmail
Venus Protocol User Drained Of $27M In Phishing Scam
GameFi Guides

Venus Protocol User Drained of $27M in Phishing Scam

by admin September 2, 2025



A BNB Chain-based Venus Protocol user has been drained of about $27 million in a phishing attack, according to on-chain data.

BSC transaction records show that a major account on the platform (0x56…2008) was likely compromised. Security firm PeckShield reported that the user appeared to approve a malicious transaction, giving the attacker control. 

Funds were then moved to the attacker’s wallet (0x7fd8…202a), which still shows holdings worth more than $27.1 million.

Most of the stolen funds are in Venus USDT (VUSDT), with over 769 million tokens valued around $19.8 million. Another 276 million Venus USDC (VUSDC), worth about $7.1 million, was also drained. Smaller amounts of Binance-Peg ETH, XRP, and BTCB were included.

PeckShield stressed that this was not a direct exploit of Venus Protocol itself, but rather a wallet-level compromise through phishing. Once approvals are granted, attackers can transfer tokens without further consent, leaving victims little recourse.

Separate Bunni Exploit Costs $2.3M

On the same day, decentralized trading platform Bunni suffered a separate breach worth about $2.3 million.

Blockchain security firm BlockSec flagged the incident, pointing to flaws in Bunni’s Ethereum-based smart contracts. The stolen funds were traced to wallet 0xE04…64f2b, which currently holds roughly $1.33 million in USDC and $1.04 million in USDT. The exact attack method has not yet been disclosed.

Both the Venus phishing scam and the Bunni exploit highlight the biggest dangers in DeFi users falling for scams and loopholes in smart contracts. With more money flowing into the space, these threats aren’t going away anytime soon. 

Note: This is a developing story. More details are anticipated.

Also Read: CertiK Flags Suspicious Activity in OLAXBT’s AIO Tokens



Source link

September 2, 2025 0 comments
0 FacebookTwitterPinterestEmail
Raoul Pal Predicts Total Crypto User Base 4B By 2030.
Crypto Trends

Raoul Pal Predicts Total Crypto User Base 4B By 2030.

by admin September 1, 2025



The total number of crypto users could hit the 4 billion mark by 2030, according to former hedge fund manager and crypto bull Raoul Pal.

In an X post on Sunday, Pal shared data comparing the adoption rate of crypto users to internet users after each innovation hit 5 million users.

Pal did this by looking at the number of crypto wallets compared to the number of IP addresses.

Source: Raoul Pal

According to Pal, the total crypto user base has grown by 137% annually in nine years and has reached 659 million users by the end of 2024. In comparison, the total number of internet users hit 187 million by the end of 2000, at an annual growth rate of 76%.

Pal predicts the number of crypto users will grow by a moderate 43% next year, reaching 1 billion crypto users by 2030, or one-eighth of the global population. 

$100 trillion market capitalization

Pal’s bullish forecast further predicts that crypto’s market capitalization could cross the $100 trillion mark within the next decade and be achieved as early as 2032.

Debasement and adoption would likely be the primary catalysts for this growth, according to Pal.

“Debasement explains 90% of price action (adoption explains 100% of outperformance vs debasement),” said Pal, who is the founder and CEO of the financial knowledge and education platforms Real Vision and Global Macro Investor.

Related:  Exponential currency debasement: ‘You don’t own enough crypto, NFTs’ 

Community taps brakes on Pal’s bullish take

Some comments on Pal’s X post, however, suggest Pal could be overestimating things. 

One X user said that wallets are not a reliable source of growth, with another suggesting that a founder of a crypto project could simply open “10000 wallets and spreading coins to make it look like he has a community.”

Another user pointed out that they create a new wallet every six months and have been doing so for the past four years.

However, Pal responded, arguing that everyone has multiple IP addresses, too. 

According to the B2B digital currency platform Triple-A, there were more than 560 million crypto users by the end of 2024.

Meanwhile, an October 2024 report by Andreessen Horowitz’s crypto division indicates roughly 30 million to 60 million real crypto users monthly.

Magazine: XRP ‘cycle target’ is $20, Strategy Bitcoin lawsuit dismissed: Hodler’s Digest, Aug. 24 – 30



Source link

September 1, 2025 0 comments
0 FacebookTwitterPinterestEmail
Satoshi or Not? First Bitcoin User Remembered on This Date
Crypto Trends

Satoshi or Not? First Bitcoin User Remembered on This Date

by admin August 28, 2025


Today, the crypto community remembers renowned cryptographer and computer scientist Hal Finney, regarded as the first Bitcoin user, who passed away exactly 11 years ago.

In a tweet, Bitcoin historian Pete Rizzo paid tribute to the Bitcoin pioneer: “Exactly 11 years ago today – Hal Finney – the 1st Bitcoin user, passed away.  He championed BTC when it was $0 and predicted $10 million BTC. Gone but not forgotten. Legend.”

Exactly 11 years ago today – Hal Finney – the 1st #Bitcoin user, passed away.

He championed BTC when it was $0 and predicted $10 million BTC.

Gone but not forgotten. Legend 🧡 pic.twitter.com/kfZ4luQ9ps

— The Bitcoin Historian (@pete_rizzo_) August 28, 2025

Finney was among the first to download, install and use the Bitcoin software when pseudonymous Bitcoin creator Satoshi Nakamoto initially released it. In his early experimentation with Bitcoin, Finney mined the cryptocurrency, finding and fixing software problems subsequently. 

You Might Also Like

However, due to excessive CPU consumption, Finney removed the Bitcoin software, but it was only for a brief period. 

Satoshi mystery remains

Finney wrote his name in the sands of time as Bitcoin founder Satoshi Nakamoto sent him the first ever Bitcoin transaction. Satoshi initiated the first transaction on the blockchain on Jan. 12, 2009, sending 10 Bitcoin to Finney, the first of what would later be regarded as a peer-to-peer (P2P) transaction. 

You Might Also Like

Finney was also among the first to reply to Satoshi Nakamoto’s publication of the white paper. 

When Bitcoin was worth cents, Finney predicted the cryptocurrency would go to millions of dollars, with a $10 million BTC prediction attributed to him.

Finney was diagnosed with amyotrophic lateral sclerosis (ALS) in 2009 and passed away on Aug. 28, 2014. Finney was speculated to be Satoshi Nakamoto, but he denied this before his passing. To date, the true identity of Satoshi Nakamoto remains a mystery yet unsolved.





Source link

August 28, 2025 0 comments
0 FacebookTwitterPinterestEmail
How Will the Israel-Iran Conflict End? Here's What AI Models Predict
NFT Gaming

Perplexity Comet Flaw Exposed User Data to Attackers, Brave Reports

by admin August 25, 2025



In brief

  • In a demo, Comet’s AI assistant followed embedded prompts and posted private emails and codes.
  • Brave says the vulnerability remained exploitable weeks after Perplexity claimed to have fixed it.
  • Experts warn that prompt injection attacks expose deep security gaps in AI agent systems.

Brave Software has uncovered a security flaw in Perplexity AI’s Comet browser that showed how attackers could trick its AI assistant into leaking private user data.

In a proof-of-concept demo published August 20, Brave researchers identified hidden instructions inside a Reddit comment. When Comet’s AI assistant was asked to summarize the page, it didn’t just summarize—it followed the hidden commands.

Perplexity disputed the severity of the finding. A spokesperson told Decrypt the issue “was patched before anyone noticed” and said no user data was compromised. “We have a pretty robust bounty program,” the spokesperson added. “We worked directly with Brave to identify and repair it.”



Brave, which is developing its own agentic browser, maintained that the flaw remained exploitable weeks after the patch and argued Comet’s design leaves it open to further attacks.

Brave said the vulnerability comes down to how agentic browsers like Comet process web content. “When users ask it to summarize a page, Comet feeds part of that page directly to its language model without distinguishing between the user’s instructions and untrusted content,” the report explained. “This allows attackers to embed hidden commands that the AI will execute as if they were from the user.”

Prompt injection: old idea, new target

This type of exploit is known as a prompt injection attack. Instead of tricking a person, it tricks an AI system by hiding instructions in plain text.

“It’s similar to traditional injection attacks—SQL injection, LDAP injection, command injection,” Matthew Mullins, lead hacker at Reveal Security, told Decrypt. “The concept isn’t new, but the method is different. You’re exploiting natural language instead of structured code.”

Security researchers have been warning for months that prompt injection could become a major headache as AI systems gain more autonomy. In May, Princeton researchers showed how crypto AI agents could be manipulated with “memory injection” attacks, where malicious information gets stored in an AI’s memory and later acted on as if it were real.

Even Simon Willison, the developer credited with coining the term prompt injection, said the problem goes far beyond Comet. “The Brave security team reported serious prompt injection vulnerabilities in it, but Brave themselves are developing a similar feature that looks doomed to have similar problems,” he posted on X.

Shivan Sahib, Brave’s vice president of privacy and security, said its upcoming browser would include “a set of mitigations that help reduce the risk of indirect prompt injections.”

“We’re planning on isolating agentic browsing into its own storage area and browsing session, so that a user doesn’t accidentally end up granting access to their banking and other sensitive data to the agent,” he told Decrypt. “We’ll be sharing more details soon.”

The bigger risk

The Comet demo highlights a broader problem: AI agents are being deployed with powerful permissions but weak security controls. Because large language models can misinterpret instructions—or follow them too literally—they’re especially vulnerable to hidden prompts.

“These models can hallucinate,” Mullins warned. “They can go completely off the rails, like asking, ‘What’s your favorite flavor of Twizzler?’ and getting instructions for making a homemade firearm.”

With AI agents being given direct access to email, files, and live user sessions, the stakes are high. “Everyone wants to slap AI into everything,” Mullins said. “But no one’s testing what permissions the model has, or what happens when it leaks.”

Generally Intelligent Newsletter

A weekly AI journey narrated by Gen, a generative AI model.



Source link

August 25, 2025 0 comments
0 FacebookTwitterPinterestEmail

Categories

  • Crypto Trends (1,098)
  • Esports (800)
  • Game Reviews (772)
  • Game Updates (906)
  • GameFi Guides (1,058)
  • Gaming Gear (960)
  • NFT Gaming (1,079)
  • Product Reviews (960)

Recent Posts

  • This 5-Star Dell Laptop Bundle (64GB RAM, 2TB SSD) Sees 72% Cut, From Above MacBook Pricing to Practically a Steal
  • Blue Protocol: Star Resonance is finally out in the west and off to a strong start on Steam, but was the MMORPG worth the wait?
  • How to Unblock OpenAI’s Sora 2 If You’re Outside the US and Canada
  • Final Fantasy 7 Remake and Rebirth finally available as physical double pack on PS5
  • The 10 Most Valuable Cards

Recent Posts

  • This 5-Star Dell Laptop Bundle (64GB RAM, 2TB SSD) Sees 72% Cut, From Above MacBook Pricing to Practically a Steal

    October 10, 2025
  • Blue Protocol: Star Resonance is finally out in the west and off to a strong start on Steam, but was the MMORPG worth the wait?

    October 10, 2025
  • How to Unblock OpenAI’s Sora 2 If You’re Outside the US and Canada

    October 10, 2025
  • Final Fantasy 7 Remake and Rebirth finally available as physical double pack on PS5

    October 10, 2025
  • The 10 Most Valuable Cards

    October 10, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • This 5-Star Dell Laptop Bundle (64GB RAM, 2TB SSD) Sees 72% Cut, From Above MacBook Pricing to Practically a Steal

    October 10, 2025
  • Blue Protocol: Star Resonance is finally out in the west and off to a strong start on Steam, but was the MMORPG worth the wait?

    October 10, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close