More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.
The leaked files represent an extensive archive of proprietary software spanning roughly ten years of development activity on Valve's Steam platform. The breach includes both unreleased beta versions and completed games from multiple developers.
The scope of the leak raises significant concerns about the security of development assets and intellectual property housed on the platform. Beta builds often contain unfinished features, debugging information, and development notes that studios typically keep confidential before official releases.
Third-party developers using Steam's infrastructure appear to have been impacted alongside Valve's own projects. The exposure of such a large volume of development files could potentially provide competitors and bad actors with insights into unreleased games, development methodologies, and security vulnerabilities.
The exact circumstances of how the files were accessed and who obtained them remain unclear. Such large-scale leaks typically result from compromised credentials, unpatched vulnerabilities, or misconfigured storage systems.
This incident follows previous security breaches affecting gaming platforms and development studios. The gaming industry has faced mounting pressure to strengthen data protection measures for unreleased titles and proprietary development tools.
The leak underscores risks associated with centralizing large amounts of sensitive development data in cloud-based platforms. Studios relying on such infrastructure face potential exposure of trade secrets, unreleased projects, and technical documentation.
Valve has not yet issued a public statement regarding the scope of the breach or remediation efforts. Affected third-party developers may face separate notification and disclosure requirements depending on their location and the nature of exposed data.
Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.
A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.
Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.
Multiple extensions in the Chrome Web Store and Microsoft Edge delivered malware that stole cryptocurrency, browser data, and user history while injecting fraudulent ClickFix lures.