Connect with us

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Powered by WPeMatico

Continue Reading
Advertisement

Industry News

Amusnet Unveils Live Casino Strategy for 2025

Published

on

amusnet-unveils-live-casino-strategy-for-2025
Reading Time: 2 minutes

 

Amusnet’s Live Casino 2025 strategy is to empower operators and differentiate their offerings with bespoke game environments, exciting gameplay and enhanced winning potential through special features and significant multipliers integrated into a variety of new releases planned for the year.

“2025 is shaping up to be an exciting year for our Live Casino division. We are introducing a diverse range of standout games that blend entertainment, technology, and interactivity in new ways,” said Marin Dimitrov, Head of Live Casino.

One of the key highlights is Showtime Roulette 500x, a fresh take on the classic roulette experience.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

“What sets Showtime Roulette 500x apart is its unparalleled customization capabilities. Operators can fully tailor the game environment to reflect their brand identity,” Dimitrov said.

This fast-paced European roulette reinvents the classics, featuring a host who presents, entertains and spins the wheel for a seamless, engaging experience. Thanks to advanced chroma technology, operators can uniquely brand the game, showcasing their logo and any bespoke background theme they desire. This creates a tailored and immersive experience that feels truly one of a kind for each operator and their players. Further enhancing player engagement, the thrill of potential rewards is heightened through random multipliers on every spin, with payouts amplified up to 500x, creating a truly exceptional gaming experience that elevates player excitement and satisfaction.

Another highlight of the year is Extra Crown Deluxe Live, which is “inspired by our slot top performer Extra Crown and offers an engaging blend of traditional slot excitement and the dynamic atmosphere of live casinos,” added Dimitrov.

This innovative live slot game retains the charm of the original while introducing upgraded mechanics and captivating gameplay. A dynamic studio setting, complete with a charismatic host, fosters a strong sense of community, bringing players together 24/7 to share in the excitement of every spin. With ten traditional symbols across 5 reels and 20 paylines, players can enjoy this classic slot action enhanced by features like Free Spins (with retrigger potential), Respins with expanding symbols and lucrative Cash Prizes (multipliers). The innovative Dynamic Reel Prizes and real-time Statistics further enhance the immersive gaming experience, topped off by the ever-popular Jackpot Cards bonus game and the chance to multiply wins via the Gamble Feature.

The latest release is Football Thrill, a high-speed live casino game that brings the excitement of football to the casino floor with instant, easy-to-play mechanics. With its simple gameplay and dynamic pacing, this Live Casino addition is designed to captivate both sports fans and casino enthusiasts. Fast, intuitive and built for excitement, this Live Casino game is the perfect addition to any live casino looking to attract players who crave action-packed, easy-to-play games.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Amusnet’s Live Casino strategy for the upcoming year centers on delivering innovative and immersive gaming experiences. This will be achieved through the introduction of enhanced roulette variations featuring captivating gameshow elements and significantly larger multipliers, boosting excitement and winning potential. The company is set to expand its offerings with a diverse selection of card games that blend classic gameplay with modern twists to appeal to both traditional and modern players. Further enhancing player engagement will be the range of interactive wheel-based games and gameshows incorporating thrilling new mechanics.

The post Amusnet Unveils Live Casino Strategy for 2025 appeared first on European Gaming Industry News.

Continue Reading

Compliance Updates

Exclusive Commentary from Vixio On Their AML Outlook Findings

Published

on

exclusive-commentary-from-vixio-on-their-aml-outlook-findings
Reading Time: 2 minutes

 

Your recent AML Outlook report highlights over €36 million in fines issued across Europe in just one year. What recurring weaknesses or compliance gaps are regulators most commonly identifying in payments and e-money firms?

John Gidla (JG): Regulators continue to flag underinvestment in anti-financial crime controls as a key concern for payments and e-money firms. Common themes include weak governance, limited oversight, and fragmented controls, all of which increase vulnerability to financial crime. There’s a growing expectation that firms scale their compliance frameworks in line with their risk exposure and growth trajectory

 

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The report mentions that AML compliance can be costly—yet the reputational and financial risks of non-compliance are even greater. What are the most cost-effective measures firms can implement today to strengthen their AML frameworks without overwhelming their budgets?

JG: While not all firms can afford advanced compliance tools, strong governance remains one of the most cost-effective ways to reduce risk. Practical steps such as training staff on emerging threats, embedding a culture of accountability, and regularly updating frameworks as the business grows can go a long way in strengthening AML resilience without major spend.

 

With the creation of the EU’s new AMLA authority, do you expect a more consistent and centralized enforcement approach across Europe? How might this change how firms prepare for inspections and adapt their compliance strategies?

JG: AMLA has the potential to bring greater consistency to AML enforcement across the EU, addressing long-standing issues caused by fragmented supervision and uneven implementation by national authorities. Its impact will depend on how much direct oversight it gains, how assertively it acts on cross-border risks, and whether it can close the regulatory gaps that have permitted high-profile scandals. Firms should expect more rigorous and standardised inspections and will need to ensure their compliance programmes are not only locally robust, but scalable across jurisdictions.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

 

Vixio emphasizes the importance of a proactive rather than reactive compliance culture. In your view, what does a ‘proactive’ AML strategy look like in 2025, and what technologies or best practices are leading firms adopting to stay ahead?

JG: A truly proactive AML strategy in 2025 extends beyond technology to encompass a strong compliance culture at every level of the organisation. Leading firms understand that combating financial crime isn’t just the responsibility of the compliance team — it’s integrated into day-to-day operations, with senior leadership driving risk awareness across departments. In terms of technology, firms are increasingly adopting AI, machine learning, and automated monitoring systems to detect suspicious activity early and reduce human error. However, culture plays a critical role; firms that foster a compliance-first mindset and invest in ongoing staff training are better positioned to adapt to emerging threats and ensure that their compliance frameworks evolve in step with business growth and digital transformation. A proactive approach also means constantly reassessing risk and using data to predict and prevent issues, rather than just reacting to them. With regulations in constant flux, and regulators ramping up enforcement, proactive compliance looks like implementing strategies to anticipate regulations, not just react to them. In Vixio’s PC Outlook Report, we found that a clear majority of firms surveyed are using some form of outsourcing for their compliance functionality, turning to firms like Vixio to get ahead of regulatory change.

 

Thanks to John Gidla, Head of Payments Compliance at Vixio, for his insightful responses.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The post Exclusive Commentary from Vixio On Their AML Outlook Findings appeared first on European Gaming Industry News.

Continue Reading

Industry News

CasinoWebScripts Enables Direct Provider Connections and Eliminates the Need for Aggregators

Published

on

casinowebscripts-enables-direct-provider-connections-and-eliminates-the-need-for-aggregators
Reading Time: 2 minutes

 

CasinoWebScripts, a leading provider of iGaming software solutions, is drawing attention to a powerful infrastructure model already in use by several clients — one that enables direct integration between online casino operators and game content providers. As the industry evolves, the company is now actively promoting this approach as a smarter alternative to traditional aggregation.

In the conventional model, aggregators act as intermediaries between content providers and casino platforms. While convenient, this structure often limits operators’ control over technical and commercial aspects, introduces latency and adds additional costs. CasinoWebScripts’ model removes the need for an aggregator by enabling operators to connect directly to game providers using a simplified and consistent integration method.

“Our goal is to simplify the way operators work with game studios, regardless of the type of casino they operate — whether it’s real-money, crypto, or social sweepstakes. By providing the tools and infrastructure for direct connections, we empower both sides to negotiate directly, optimize performance, and reduce third-party dependencies,” said Oscar Stevens, Head of Business Development at CasinoWebScripts.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Key Features of the Model Include:

• Direct Integration: Operators connect with game providers through a unified framework, without using an aggregator.

• Faster Load Times and Lower Latency: The streamlined architecture improves game performance and platform responsiveness.

• Independent Commercial Agreements: Operators and providers manage their own contracts, pricing and terms with full autonomy.

• Easy Expansion: The system supports the quick addition of new providers, with minimal integration overhead.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

• Technology-Only Role: CasinoWebScripts supplies the infrastructure but does not interfere in commercial relationships.

This infrastructure shift reflects growing demand from operators looking for more autonomy in their business models. It also addresses concerns about transparency and technical bottlenecks that often arise with aggregator-based systems.

“Our platform is designed to serve those who want to scale fast and retain control over their operations. With this model, operators no longer have to compromise on performance or commercial independence,” added Stevens.

The post CasinoWebScripts Enables Direct Provider Connections and Eliminates the Need for Aggregators appeared first on European Gaming Industry News.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading

Trending

Get it on Google Play

Fresh slot games releases by the top brands of the industry. We provide you with the latest news straight from the entertainment industries.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Recent Slot Releases is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania