Security News

Disgruntled bug-hunter drops Steam zero-day to get back at Valve for refusing him a bounty
2019-08-22 05:16

EoP bug now free for the world to see after bounty was rejected A security bod angry at Valve's handling of bug reports has released a zero-day vulnerability affecting the games giant's flagship...

Researcher Discloses Second Steam Zero-Day After Valve Bug Bounty Ban
2019-08-21 20:40

After Valve banned him from its bug bounty program, a researcher has found a second zero-day vulnerability affecting the Steam gaming client.

Valve Patches 10-Year Old Flaw in Steam Client
2018-05-31 16:42

A remote code execution (RCE) vulnerability that existed in the Steam client for at least 10 years was fully patched only in March this year, according to security firm Context Information Security.

Valve Patches Trivial XSS Bug in Steam (Threatpost)
2017-02-08 17:00

A cross-site scripting vulnerability on the Steam gaming platform has been patched. The flaw could be exploited by simply viewing a crafted profile.

Student bypasses Valve’s review process, publishes game on Steam (Help Net Security)
2016-03-30 20:58

Sometimes the only way to get an organization to listen to you when it comes to existing vulnerabilities in their products is to exploit them yourself and make the proof of the exploitation...

Valve Patches Password Reset Vulnerability in Steam (Threatpost)
2015-07-27 18:06

Valve Software has patched a vulnerability in the Steam gaming platform that enabled account hijacking through its password reset mechanism.