RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how.

Read More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
AppSec & Supply Chain SecurityAugust 17, 2023

The Week in Security: Researchers hack 'unbreakable' card-shuffling hardware, Discord.io shut after breach

A Week of Breaches: The Intersection of Physical and Digital Security Failures

Kate Tenerowicz black white headshot
Kate TenerowiczKate Tenerowicz
FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
deck mate 2 cards shuffler on green felt table

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security. This week: Researchers kick it Ocean's Eleven style with an attack on card shuffling machines. Also: A software vulnerability could be behind a breach that shut down Discord's invite system.

This Week’s Top Story

Hackers Rig Casino Card-Shuffling Machines for ‘Full Control’ Cheating

History has shown us that there are few better ways of getting a piece of technology hacked than to declare it secure and "un-hackable." The latest case in point: the Deckmate 2, an automated card shuffling machine used in casinos around the world. After an investigation into an alleged incident of cheating in a high stakes poker tournament prompted an official investigation that declared the Deckmate shuffling machine one that "is secure and cannot be compromised,” three IOActive researchers took up the implicit challenge. Spoiler alert: the Deckmate was, in fact, hackable.

At a presentation at Black Hat, researchers Joseph Tartaro, Enrique Nissim and Ethan Shackelford of IOActive presented the results of a months-long investigation into the Deckmate. As reported by WIRED, the three found attackers could employ a simple USB-enabled minicomputer to gain total control over the machine, potentially allowing a poker player to know exactly what cards the dealer and other players hold and, thus, become unstoppable at the table.

Tartaro and his fellow researchers were able to alter the shuffler’s code to hijack the machine, and tamper the shuffling process. They also were able to access an internal camera on the Deckmate, giving them the ability to know exactly which cards were being dealt and to whom. However, as of yet the IOActive researchers have not been able to engineer a technique that allows for them to choose the exact order of cards via this remote access. Light & Wonder, the makers of Deckmate, said in emails to the researchers that they are in the process of patching the issues discovered by the researchers. The company denies the compromises have been used against machines deployed on a casino floor.

News Roundup

Here are the stories we’re paying attention to this week…

Discord.io Temporarily Shuts Down Amid Breach Investigation (Dark Reading)

Discord.io — a third-party service that allows for people to send Discord invites — has gone offline for the foreseeable future after a security breach that saw the information of 760,000 users downloaded by malicious actors and posted for sale on the dark web. No one has claimed credit for the attack, but the company believes the breach was made possible by a vulnerability in their code. The stolen information includes both sensitive and nonsensitive data including usernames, Discord IDs, email addresses, billing addresses, and passwords as well as coin balances, API keys, and more.

Hacktivists attack Japanese government over Fukushima wastewater release (The Register)

Operation ‘Tango Down’ launched this month. Run by hacktivist group The Anonymous Italia Collective, the operation included "cyber protests," (aka "attacks") against 21 facilities and websites associated with the Fukushima Daini Nuclear Power Plant. The group and operation is responding to the decision by the power plant, Japanese government, and the International Atomic Energy Agency to allow the release of a million tons of treated — radioactive — wastewater into the environment.

Threat actors use beta apps to bypass mobile app store security (Bleeping Computer)

The Federal Bureau of Investigation (FBI) issued a warning about malicious ‘beta’ versions of cryptocurrency investment apps that are promoted on popular mobile app stores by cybercriminals. The ‘beta’ versions are actually malware that is designed to steal cryptocurrencies, and personal identifiable information (PII). The reason these applications even make it on the app stores, is due to the ‘beta’ label which allows them to bypass the normal rigorous code review process.

QwixxRAT: New Remote Access Trojan Emerges via Telegram and Discord (The Hacker News)

A new remote access trojan (RAT) called QwixxRAT is being advertised for sale on Telegram and Discord platforms. The trojan is available in a limited free version, weekly access to the complete version for 150 rubles ($1.60 USD), and lifetime access for 500 rubles ($5.35 USD). Once installed onto Windows platform machines, the RAT stealthily collects sensitive data, which is then sent to the attackers. The data it collects can be any combination of browser histories, bookmarks, cookies, credit card information, keystrokes, screenshots, files matching certain extensions, and data from various applications.

Microsoft Cloud Security Woes Inspire DHS Security Review (Dark Reading)

The US Department of Homeland Security (DHS) last week kicked off an investigation into the threat of cyberattacks against cloud computing environments. The announcement followed criticism of Microsoft’s handling of a major Azure cloud infrastructure attack. On August 11th, U.S. Secretary of Homeland Security Alejandro N. Mayorkas announced that the Cyber Safety Review Board (CSRB) will conduct its next review on the malicious targeting of cloud computing environments. In particular, CSRB will "assess the recent Microsoft Exchange Online intrusion, initially reported in July 2023, and conduct a broader review of issues relating to cloud-based identity and authentication infrastructure affecting applicable CSPs and their customers," the statement said. CSRB will develop "actionable recommendations" to advance cybersecurity practices for both cloud computing customers and cloud service providers, Mayorkas said.

Keep learning

  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Get key insights into why Gartner® identified binary analysis as a must-have control in its recent CISO Playbook for Commercial Software Supply Chain Security.
  • Get up to speed on the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the the webinar discussing the findings.

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Plus: Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Tags:AppSec & Supply Chain Security

More Blog Posts

OSS security

Should frontier AI firms fund OSS ecosystem security?

With a ‘vulnpocalypse’ expected, AppSec leaders are calling for the companies to invest in a Great Refactor Fund to secure open source.

Learn More about Should frontier AI firms fund OSS ecosystem security?
Should frontier AI firms fund OSS ecosystem security?
Agentic AI architecture

Agentic AI risk isn't a model problem. It's an architecture problem.

Agentic AI is moving the perimeter from components to data — and most strategies aren't built for that.

Learn More about Agentic AI risk isn't a model problem. It's an architecture problem.
Agentic AI risk isn't a model problem. It's an architecture problem.
AI coding agents

The race to secure AI coding: 4 steps to rein agents in

Coding agents are privileged insiders — with keys to CI/CD pipelines even as they give rise to ‘slopsquatting.’ Here’s how to govern them.

Learn More about The race to secure AI coding: 4 steps to rein agents in
The race to secure AI coding: 4 steps to rein agents in
Shai-hulud worm DevOps

Update to npm blocks install scripts: What it means for AppSec

Disabling scripts by default closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.

Learn More about Update to npm blocks install scripts: What it means for AppSec
Update to npm blocks install scripts: What it means for AppSec

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top