Scworld DDoS Botnet Exploits Jenkins to Target Valve Game Servers
Article Content
- •A new DDoS botnet targets Valve's game servers via exposed Jenkins servers.
- •The malware can perform multiple types of DDoS attacks, including UDP and TCP floods.
- •Security researchers detected the threat through honeypot systems, indicating active exploitation.
A new DDoS botnet has been identified that exploits misconfigured Jenkins servers to launch attacks on Valve's Source Engine game infrastructure, affecting popular games like Counter-Strike and Team Fortress 2. The malware is capable of executing UDP, TCP, and application-layer floods, demonstrating the dangers of insecure continuous integration (CI) servers. Security researchers from Darktrace discovered the threat after monitoring it on their honeypot systems. This campaign highlights the potential for a single exposed CI server to be transformed into a multi-platform attack node. The exact scale of the attacks and the number of affected servers remain unclear, but the targeted nature of the malware poses significant risks to online gaming environments. As of now, there are no specific CVEs or patches reported for this vulnerability. Organizations using Jenkins are advised to review their configurations to prevent exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Valve in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…