Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Pricing Choices and Useful Scope

    January 25, 2026

    The cybercrime business continues to problem CISOs in 2026

    January 25, 2026

    Conversational AI doesn’t perceive customers — 'Intent First' structure does

    January 25, 2026
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»Ubisoft Shuts Down Rainbow Six Siege After MongoDB Exploit Hits Gamers – Hackread – Cybersecurity Information, Information Breaches, AI, and Extra
    AI Ethics & Regulation

    Ubisoft Shuts Down Rainbow Six Siege After MongoDB Exploit Hits Gamers – Hackread – Cybersecurity Information, Information Breaches, AI, and Extra

    Declan MurphyBy Declan MurphyDecember 29, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Ubisoft Shuts Down Rainbow Six Siege After MongoDB Exploit Hits Gamers – Hackread – Cybersecurity Information, Information Breaches, AI, and Extra
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Hundreds of players discovered themselves locked out of their accounts this week after a serious safety flaw pressured Ubisoft to tug the plug on its hit recreation, Rainbow Six Siege. For individuals who don’t observe the gaming world, Siege is an enormous tactical shooter recreation the place groups work collectively to storm or defend buildings. It’s a flagship title for Ubisoft, however over the vacation weekend, it grew to become essentially the most seen sufferer of a newly found vulnerability in MongoDB software program, dubbed MongoBleed.

    We’re conscious of an incident presently affecting Rainbow Six Siege. Our groups are engaged on a decision.

    We’ll share additional updates as soon as out there.

    — Rainbow Six Siege X (@Rainbow6Game) December 27, 2025

    What is occurring?

    To place it merely, MongoDB is a well-liked database software program utilized by 1000’s of firms to retailer every little thing from buyer addresses to recreation progress. The issue, formally tracked as CVE-2025-14847, entails a software known as zlib that MongoDB makes use of to “shrink” information for quicker journey.

    A mistake within the code permits an outsider to ship a corrupted message that methods the server into “bleeding” out fragments of its personal inside reminiscence. As a result of this occurs earlier than the system even asks for a password, it permits unauthenticated hackers to sneak out delicate info from wherever on the planet. This leaked reminiscence can expose:

    • Clear-text passwords and login keys.
    • Private buyer info (PII).
    • Safety tokens that enable hackers to impersonate actual customers.

    The Chaos at Ubisoft

    You may surprise how a database vulnerability can shut down a online game. Ubisoft makes use of MongoDB to retailer participant information, like your rank or the gadgets you’ve unlocked. Based on the web malware repository, VX-Underground, totally different hacker teams have up to now used the MongoBleed vulnerability to realize a backdoor into the sport’s inside techniques.

    Clarification publish, earlier publish about Ubisoft result in some confusion. That is my fault. I will be extra verbose. I used to be attempting to compress the data into 1 singular publish with out it exceeding the phrase restrict.

    Here is the phrase on the web streets:
    – THE FIRST GROUP of… pic.twitter.com/crsOxCnMWU

    — vx-underground (@vxunderground) December 27, 2025

    As soon as inside, the hackers went on a spree; they hijacked the ban ticker to point out pretend messages and unban their mates, unlocked each single beauty outfit and merchandise for themselves, and gifted a staggering 2 billion R6 Credit (in-game forex) to gamers.

    Looks as if R6 is totally fucked. It’s unreal how unhealthy.

    Hackers have accomplished the next.

    1. Banned + unbanned 1000’s of individuals.
    2. Taken over the ban feed can put something.
    3. Gave everybody 2 billion credit + renown.
    4. Gave everybody each pores and skin together with dev skins.

    — KingGeorge (@KingGeorge) December 27, 2025

    Ubisoft was pressured to take your complete recreation and its Market offline to cease the bleeding. Whereas they gained’t punish gamers who spent the “free” cash, they’re presently working to roll again all transactions that occurred through the breach.

    Energetic Assaults within the Wild

    Whereas the flaw was first disclosed on December 19, 2025, the scenario turned crucial on December 26 when researcher Joe Desimone printed the assault blueprint (public exploit code) on GitHub. Because the launch, consultants at Wiz and Censys have famous an enormous spike in assaults. They estimate that 42% of cloud setups are in danger, with over 87,000 databases presently sitting uncovered on the web.

    How one can Keep Protected

    Whereas older variations (like 3.6 or 4.2) haven’t any official repair, newer variations have been patched. To remain secure, it’s essential to replace to variations 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.

    If you happen to can’t replace instantly, consultants recommend turning off the zlib compression setting in your database as a brief defend to dam attackers.

    Picture credit: Censys and CyberSecurityNews

    Ben Ronallo, Principal Cybersecurity Engineer at Black Duck, a Burlington, Massachusetts-based supplier of utility safety options, additionally commented on the difficulty, stating, “The risk actors have been intelligent; they attacked through the holidays when many firms are typically much less responsive resulting from workers taking time without work. Ubisoft seems to be the very best profile sufferer at this level.“

    Ronallo additionally shared steps for safety groups to workaround the difficulty, together with:

    • Verify you probably have any internet-facing techniques with a susceptible model of a MongoDB occasion hooked up.
    • If you happen to discover any such techniques, instantly kick off your incident response efforts to establish any potential compromise and include the harm.
    • There’s this open-source software that may be leveraged to investigate MongoDB logs for indicators of compromise.
    • Any susceptible variations ought to be patched instantly utilizing official fixes from MongoDB.



    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    The cybercrime business continues to problem CISOs in 2026

    January 25, 2026

    FBI Accessed Home windows Laptops After Microsoft Shared BitLocker Restoration Keys – Hackread – Cybersecurity Information, Information Breaches, AI, and Extra

    January 25, 2026

    Multi-Stage Phishing Marketing campaign Targets Russia with Amnesia RAT and Ransomware

    January 25, 2026
    Top Posts

    Pricing Choices and Useful Scope

    January 25, 2026

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025
    Don't Miss

    Pricing Choices and Useful Scope

    By Amelia Harper JonesJanuary 25, 2026

    SweetAI is offered as a chatbot designed for customers in search of interplay that doesn’t…

    The cybercrime business continues to problem CISOs in 2026

    January 25, 2026

    Conversational AI doesn’t perceive customers — 'Intent First' structure does

    January 25, 2026

    FBI Accessed Home windows Laptops After Microsoft Shared BitLocker Restoration Keys – Hackread – Cybersecurity Information, Information Breaches, AI, and Extra

    January 25, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2026 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.