Casino High-Stakes Online Poker Malware Scandal Exposes Players' Hole Cards
Article Content
- •A malware attack allowed a cheater to view high-stakes poker players' hole cards in real time.
- •The attack exploited vulnerabilities in Jurojin Poker and IntuitiveTables software via tampered updates.
- •Cybersecurity expert WolfSec0x0 identified 10 to 30 affected computers across Europe, North America, and Oceania.
A targeted malware attack has compromised high-stakes online poker players, allowing a cheater to view their hole cards in real time. The attacker exploited vulnerabilities in third-party software, specifically Jurojin Poker and IntuitiveTables, to deliver tampered updates containing remote-access tools. Jurojin Poker confirmed that between June 2025 and January 2026, a select group of users received these compromised updates. Cybersecurity expert WolfSec0x0 first reported the incident, identifying between 10 and 30 affected computers across multiple regions. The malware, based on legitimate software MeshCentral, enabled the attacker to remotely access players' screens. The investigation is ongoing, with Jurojin cooperating with law enforcement and poker-site security teams to address the issue. Players have raised suspicions about certain accounts showing implausibly strong results, leading to further scrutiny.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Absolute Poker in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which software was compromised?
How many players were impacted?
What should affected players do?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…